> cat /dev/github | grep security-tools
discovered 03 Aug 2026

0-click-RCE-Exploit-for-CVE-2024-10924

PHP ★ 14 via github-topic
→ View on GitHub
This repository provides a proof-of-concept exploit for CVE-2024-10924, allowing an attacker to bypass authentication and two-factor authentication in the Really Simple Security WordPress plugin to achieve remote command execution (RCE). The script automates the process of impersonating an administrator, uploading a malicious plugin, verifying interaction with the payload, and establishing an interactive remote shell. Notably, it operates pre-authentication, requiring only the target URL and a malicious plugin as input.