{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/automatic--3.92.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:valvepress:automatic:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.9,"id":"CVE-2024-27956"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Automatic (\u003c= 3.92.0)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","vulnerability","rce","web-application"],"_cs_type":"advisory","_cs_vendors":["Valvepress"],"content_html":"\u003cp\u003eCVE-2024-27956 is a critical security vulnerability affecting the Valvepress Automatic plugin for WordPress, specifically versions 3.92.0 and earlier. With a CVSS score of 9.9, this vulnerability permits unauthenticated remote attackers to execute arbitrary code over the network. The vulnerability has been confirmed by the public release of proof-of-concept (PoC) exploit scripts, significantly lowering the barrier for exploitation by malicious actors. Organizations running instances of WordPress with the affected Automatic plugin are at high risk of system compromise, as the vulnerability does not require any user interaction or authenticated privileges. Given the high EPSS score and public availability of exploit tools, immediate remediation is required for all affected installations.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2024-27956 allows an attacker to achieve unauthenticated remote code execution on the underlying server. This can lead to full site takeover, data exfiltration of the WordPress database, lateral movement within the hosting environment, and the deployment of persistent backdoors. Given the widespread use of WordPress plugins, this vulnerability presents a high risk to organizations across various sectors utilizing the affected software.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all WordPress installations within the organization using the Valvepress Automatic plugin.\u003c/li\u003e\n\u003cli\u003eUpdate the Valvepress Automatic plugin to a version beyond 3.92.0 immediately to mitigate the underlying vulnerability.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous POST requests directed at plugin-specific endpoints, particularly those originating from unknown or suspicious IP addresses.\u003c/li\u003e\n\u003cli\u003eGiven the public availability of PoC scripts, implement temporary Web Application Firewall (WAF) rules to block suspicious patterns targeting the plugin if patching cannot be performed immediately.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-30T15:14:38Z","date_published":"2026-08-30T15:14:38Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-27956/","summary":"CVE-2024-27956 is a critical vulnerability in the Valvepress Automatic WordPress plugin (versions 3.92.0 and earlier) that allows unauthenticated remote code execution via a publicly available exploit.","title":"Critical RCE Vulnerability in Valvepress Automatic Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2024-27956/"}],"language":"en","title":"CraftedSignal Threat Feed - Automatic (\u003c= 3.92.0)","version":"https://jsonfeed.org/version/1.1"}