Skip to content
Threat Feed
critical advisory

Critical RCE Vulnerability in Valvepress Automatic Plugin

CVE-2024-27956 is a critical vulnerability in the Valvepress Automatic WordPress plugin (versions 3.92.0 and earlier) that allows unauthenticated remote code execution via a publicly available exploit.

CVE search metadata

CVE search record: CVE-2024-27956. Severity: critical. CVSS: 9.9. EPSS: 93.97%. KEV: no. Product: Automatic (<= 3.92.0). Brief: Critical RCE Vulnerability in Valvepress Automatic Plugin. Brief link: https://feed.craftedsignal.io/briefs/2026-08-cve-2024-27956/

CVE-2024-27956 is a critical security vulnerability affecting the Valvepress Automatic plugin for WordPress, specifically versions 3.92.0 and earlier. With a CVSS score of 9.9, this vulnerability permits unauthenticated remote attackers to execute arbitrary code over the network. The vulnerability has been confirmed by the public release of proof-of-concept (PoC) exploit scripts, significantly lowering the barrier for exploitation by malicious actors. Organizations running instances of WordPress with the affected Automatic plugin are at high risk of system compromise, as the vulnerability does not require any user interaction or authenticated privileges. Given the high EPSS score and public availability of exploit tools, immediate remediation is required for all affected installations.

Impact

Successful exploitation of CVE-2024-27956 allows an attacker to achieve unauthenticated remote code execution on the underlying server. This can lead to full site takeover, data exfiltration of the WordPress database, lateral movement within the hosting environment, and the deployment of persistent backdoors. Given the widespread use of WordPress plugins, this vulnerability presents a high risk to organizations across various sectors utilizing the affected software.

Recommendation

Prioritized, concrete actions for detection engineering and security teams:

  • Identify all WordPress installations within the organization using the Valvepress Automatic plugin.
  • Update the Valvepress Automatic plugin to a version beyond 3.92.0 immediately to mitigate the underlying vulnerability.
  • Monitor web server access logs for anomalous POST requests directed at plugin-specific endpoints, particularly those originating from unknown or suspicious IP addresses.
  • Given the public availability of PoC scripts, implement temporary Web Application Firewall (WAF) rules to block suspicious patterns targeting the plugin if patching cannot be performed immediately.

Immediate actions

Upgrade Valvepress Automatic plugin to current version

IT Operations 24h

Mitigations

Block unauthenticated external access to WordPress administrative and plugin endpoints via WAF

immediate SOC

CVE-2024-27956