S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Dec 4, 2025

CVE-2024-6220 Scanner

CVE-2024-6220 Scanner - Unrestricted File Upload vulnerability in WordPress Keydatas

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.3k
Times Used
continuous scan runs
5.8k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6220
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The 简数采集器 (Keydatas) plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the keydatas_downloadImages function in all versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
简数采集器by zhengdon
0
Updated Sep 10, 2026View on NVD →
Detail

The WordPress Keydatas plugin offers a suite of functionalities designed for data collection in Chinese websites. It aids webmasters by facilitating tasks like downloading and managing digital content seamlessly. Used extensively by organizations in China, this plugin helps circumvent data management complexities inherent in WordPress systems. With its popularity, the plugin appeals to a wide user base that ranges from corporate entities to individual blog owners. It is pivotal for data-driven operations on WordPress platforms, intended to ease content administration, and enhance the user interface by streamlining digital workflows.

The vulnerability arises from the plugin's inadequate validation mechanisms during the file upload process. Malicious actors may exploit this to upload arbitrary files due to lack of checks on the file type. This unrestricted file upload vulnerability could lead to severe threats such as unauthorized access, data theft, or even full system compromise. It represents a significant security flaw, particularly because it can be exploited without authentication. As a critical vulnerability, it demands immediate attention and remediation to prevent potential exploits.

Technically, the vulnerability is located in the `keydatas_downloadImages` function, where file-type validation is conspicuously absent. Attackers can use specially crafted requests to push arbitrary files, including malicious scripts, onto the server. The HTTP/POST parameters like `__kds_docImgs` and `__kds_download_imgs_flag` play a role in executing the unrestricted file upload. The server's failure to check the nature and content of uploaded files could permit remote code execution capabilities. Once these files are uploaded, they can be accessed through predictable URLs, making exploitation easier.

If exploited, attackers could perform remote code executions leading to site takeover or defacement. Sensitive information stored on the server could be extracted, and backdoors may be installed for continued access. Further exploitation could enable attackers to manipulate or delete critical files, disrupt server operations, and compromise user data integrity. Continued occurrences could potentially damage the website's reputation, reduce user trust, and incur financial losses due to extended downtime or data recovery expenses.

REFERENCES

Solution Advice
  • Update to the latest version of the WordPress Keydatas plugin that addresses the file upload vulnerability.
  • Implement server-side file type validations to ensure only permitted file types are uploaded.
  • Regularly monitor and audit server logs to detect anomalies or unauthorized file accesses.
  • Apply a web application firewall (WAF) to filter potentially malicious traffic and file uploads.
  • Utilize a secure environment for file storage, separating uploaded files from executable directories.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-6220 Scanner - Unrestricted File Upload vulnerability in WordPress Keydatas | S4E