S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 22, 2024

CVE-2024-9234 Scanner

CVE-2024-9234 Scanner - Arbitrary File Upload vulnerability in GutenKit

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-9234
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to arbitrary file uploads due to a missing capability check on the install_and_activate_plugin_from_external() function (install-active-plugin REST API endpoint) in all versions up to, and including, 2.1.0. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins, or utilize the functionality to upload arbitrary files spoofed like plugins.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editorby ataurr
0
gutenkitby wpmet
0
Updated Sep 10, 2026View on NVD →
Detail

GutenKit is a popular plugin for WordPress that enhances the Gutenberg Block Editor. It is widely used by web developers, content creators, and website owners to create and style web pages through blocks, patterns, and templates within the WordPress platform. The plugin enables users to customize their WordPress sites efficiently, making it a favorite tool among non-coders. Its extensive range of features aims to simplify website design and page building, thus boosting productivity for users who manage multiple sites. Integrations with additional WordPress features and third-party products further extend its functionality. GutenKit's flexibility caters to various professionals, from beginners to advanced developers, aiming to optimize their web presence.

This scanner detects an arbitrary file upload vulnerability in GutenKit. The vulnerability arises from a missing capability check in the install_and_activate_plugin_from_external() function, specifically within the install-active-plugin REST API endpoint. Without proper validation, this flaw permits unauthenticated attackers to upload or activate unauthorized plugins by exploiting this endpoint. Such a loophole exists due to inadequate security checks, making the application susceptible to nefarious file upload actions. This vulnerability affects all versions of the plugin up to and including 2.1.0.

The technical flaw exploits the install-active-plugin REST API endpoint of GutenKit. Specifically, the vulnerability allows attackers to upload files disguised as plugins through HTTP requests. The endpoint fails to conduct rigorous checks on user capabilities, which typically verify user permissions before permitting file uploads. As a result, files uploaded with malicious intent can bypass security protocols by mimicking regular, authorized plugin files. Once uploaded, these files can execute arbitrary commands or expose sensitive data, leading to severe security impacts.

Exploiting this vulnerability can significantly compromise a WordPress site. Unauthorized file uploads can introduce malicious code, leading to remote code execution or the exploitation of privileged access. This can enable attackers to manipulate site content, perform data theft, or spread malware to visitors. Moreover, executing arbitrary files poses risks of server backdoors being installed or crucial files being altered without detection. Such breaches jeopardize the site's integrity, user trust, and compliance with cybersecurity standards.

REFERENCES

Solution Advice
  • Update the GutenKit plugin to the latest version where this vulnerability is patched.
  • Implement stricter access controls and validation checks for plugin endpoints.
  • Restrict file uploads to authenticated users only, validating their permissions beforehand.
  • Regularly audit and review security configurations to prevent unauthorized access.
  • Consider leveraging security plugins for WordPress to detect and mitigate upload threats.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.