CVE-2024-27956

WordPress Automatic plugin <= 3.92.0 - Unauthenticated Arbitrary SQL Execution vulnerability

Basic Information

CVE State
PUBLISHED
Reserved Date
February 28, 2024
Published Date
March 21, 2024
Last Updated
August 02, 2024
Vendor
ValvePress
Product
Automatic
Description
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ValvePress Automatic allows SQL Injection.This issue affects Automatic: from n/a through 3.92.0.
Tags
wordpress nuclei_scanner metasploit_scanner malware xtw

CVSS Scores

CVSS v3.1

9.9 - CRITICAL

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:L

EPSS Score

Score
93.55% (Percentile: 99.82%) as of 2025-06-12

SSVC Information

Exploitation
none
Automatable
Yes
Technical Impact
partial

Exploit Status

Exploited in the Wild
Yes (2025-05-15 00:00:00 UTC) Source
Used in Malware
Yes (added 2024-04-24 00:00:00 UTC) (xtw)

Known Exploited Vulnerability Information

Source Added Date
The Shadowserver (via CIRCL) 2025-05-15 00:00:00 UTC

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

wp_automatic_sqli_to_rce

Type: metasploit • Created: Unknown

Metasploit module for CVE-2024-27956

ThatNotEasy/CVE-2024-27956

Type: github • Created: 2024-07-11 14:17:23 UTC • Stars: 7

Perform with massive Wordpress SQLI 2 RCE

itzheartzz/MASS-CVE-2024-27956

Type: github • Created: 2024-06-09 07:21:44 UTC • Stars: 2

diego-tella/CVE-2024-27956-RCE

Type: github • Created: 2024-05-01 01:58:28 UTC • Stars: 85

PoC for SQL Injection in CVE-2024-27956

truonghuuphuc/CVE-2024-27956

Type: github • Created: 2024-04-27 11:03:36 UTC • Stars: 18

CVE-2024-27956 WordPress Automatic < 3.92.1 - Unauthenticated SQL Injection

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Used in xtw Malware

  • Detected by Nuclei

  • Detected by Metasploit

  • Added to KEVIntel