S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated May 31, 2025

CVE-2024-10571 Scanner

CVE-2024-10571 Scanner - Local File Inclusion (LFI) vulnerability in Chartify - WordPress Chart Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.5k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-10571
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The Chartify – WordPress Chart Plugin plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.9.5 via the 'source' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Chartify – WordPress Chart Pluginby ays-pro
0
chartifyby ays-pro
0
Updated Sep 10, 2026View on NVD →
Detail

Chartify - WordPress Chart Plugin is commonly utilized by website administrators and developers to create and manage charts on WordPress-powered websites efficiently. It is developed by Ays-Pro and offers a range of functionalities to facilitate dynamic chart creation and seamless integration into WordPress environments. With its intuitive interface, the plugin is popular among WordPress users aiming to visualize data in an engaging manner. Organizations and individuals who manage WordPress sites often rely on such plugins to enhance user interaction by showcasing data trends and insights visually. Consequently, the plugin has found its place in diverse industries, including education, finance, and e-commerce, facilitating data-driven decision-making processes.

The Local File Inclusion (LFI) vulnerability in the Chartify - WordPress Chart Plugin allows unauthorized attackers to include arbitrary files from the server. This occurs via the 'source' parameter, leading to potential execution of malicious PHP code. Such vulnerabilities can circumvent access controls and expose sensitive information or allow remote code execution. It poses a threat to servers by potentially granting attackers unauthorized access and control over server functionalities. The ramifications of this flaw can be severe, as it can facilitate further attacks or unauthorized data access, thus compromising the security and integrity of the affected systems.

Technically, this vulnerability can be exploited through crafted HTTP POST requests to the WordPress admin-ajax.php with specific parameters. The 'source' parameter is vulnerable, allowing path traversal attacks to access and execute files outside the intended directory. An attacker can leverage this by uploading files to locations accessible by the web server and including them via the vulnerable parameter. The presence of PHPSESSID in the header response indicates successful exploitation. Additionally, the vulnerability can be used to access files related to the plugin's functionality, such as "ays-chart-heading-box" components, potentially leading to unauthorized data inclusion.

Exploiting this vulnerability can have various serious effects, including unauthorized access to sensitive data and files on the server, execution of malicious scripts, and potentially full control over the affected server. The exploitation can lead to data breaches, loss of confidentiality, and integrity of sensitive information stored on the WordPress site. Attackers may use this foothold to launch further attacks on internal networks or other connected systems. The compromise of a WordPress server through this plugin can have cascading effects, disrupting business operations and damaging reputation significantly.

REFERENCES

Solution Advice
  • Update the Chartify - WordPress Chart Plugin to the latest version to mitigate the vulnerability.
  • Ensure proper file permission settings to restrict unauthorized access to sensitive directories and files.
  • Employ security plugins for WordPress to monitor and block suspicious activities.
  • Regularly audit and review the use of third-party plugins to ensure they comply with security best practices.
  • Implement web application firewall (WAF) rules to prevent path traversal and unauthorized file inclusion attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-10571 Scanner - Local File Inclusion (LFI) vulnerability in Chartify - WordPress Chart Plugin | S4E