discovered 03 Aug 2026
0-click-RCE-Exploit-for-CVE-2024-10924
→ View on GitHubThis repository provides a proof-of-concept exploit for CVE-2024-10924, allowing an attacker to bypass authentication and two-factor authentication in the Really Simple Security WordPress plugin to achieve remote command execution (RCE). The script automates the process of impersonating an administrator, uploading a malicious plugin, verifying interaction with the payload, and establishing an interactive remote shell. Notably, it operates pre-authentication, requiring only the target URL and a malicious plugin as input.