S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Jul 2, 2024

CVE-2024-27954 Scanner

CVE-2024-27954 scanner - Arbitrary File Download and SSRF vulnerability in WordPress Automatic Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.7k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-27954
9.3
CVSScritical
Exploitable remotely over the internet · no authentication required.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WP Automatic Automatic allows Path Traversal, Server Side Request Forgery.This issue affects Automatic: from n/a through 3.92.0.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Automaticby WP Automatic
n/a
automaticby wp_automatic
0
Updated Aug 22, 2026View on NVD →
Detail

The WordPress Automatic Plugin is widely used by website administrators to automate content posting on WordPress sites. It is typically utilized by bloggers, e-commerce site owners, and digital marketers to streamline their content management processes. The plugin supports various content sources, including RSS feeds, Amazon, ClickBank, and more. Its flexibility and ease of use make it popular among users looking to automate their website content. However, vulnerabilities in such plugins can pose significant security risks.

The identified vulnerability in the WordPress Automatic Plugin allows for Arbitrary File Download and Server-Side Request Forgery (SSRF). These vulnerabilities can be exploited by attackers to download sensitive files and perform unauthorized actions on the server. The issue is located in the downloader.php file of the plugin, which fails to properly validate user input. This vulnerability has been addressed in version 3.92.1 of the plugin.

The vulnerability is found in the downloader.php file of the WordPress Automatic Plugin. The plugin fails to properly sanitize and validate user inputs, allowing attackers to craft malicious requests. By exploiting this flaw, an attacker can download arbitrary files from the server, including sensitive configuration files and user data. Additionally, the vulnerability enables SSRF, which can be used to interact with internal services and potentially escalate attacks. The vulnerable parameter is 'wp_automatic' used in the GET request.

If exploited, this vulnerability could allow attackers to access sensitive information such as login credentials, configuration files, and other confidential data stored on the server. The Arbitrary File Download flaw can lead to data breaches and unauthorized access. The SSRF aspect of the vulnerability can enable attackers to perform further internal attacks, such as accessing internal networks, services, or even exploiting other vulnerabilities within the network.

By using the S4E platform, you can ensure your digital assets are continuously monitored for vulnerabilities like those found in the WordPress Automatic Plugin. Our comprehensive scanning capabilities help you identify and mitigate security risks before they can be exploited. Becoming a member of our platform provides you with regular security reports, expert recommendations, and peace of mind knowing your assets are protected against emerging threats. Join S4E today to stay ahead of cyber threats and safeguard your online presence.

References:

Solution Advice
  • Update the WordPress Automatic Plugin to version 3.92.1 or later.
  • Regularly review and audit installed plugins for security updates and patches.
  • Implement proper input validation and sanitization in custom plugins and themes.
  • Limit the permissions of plugins to the minimum necessary to reduce potential impact.
  • Regularly back up your WordPress site and store backups in a secure, offsite location.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.