<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Automatic (&lt;= 3.92.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/automatic--3.92.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 30 Aug 2026 15:14:38 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/automatic--3.92.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Critical RCE Vulnerability in Valvepress Automatic Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-08-cve-2024-27956/</link><pubDate>Sun, 30 Aug 2026 15:14:38 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cve-2024-27956/</guid><description>CVE-2024-27956 is a critical vulnerability in the Valvepress Automatic WordPress plugin (versions 3.92.0 and earlier) that allows unauthenticated remote code execution via a publicly available exploit.</description><content:encoded><![CDATA[<p>CVE-2024-27956 is a critical security vulnerability affecting the Valvepress Automatic plugin for WordPress, specifically versions 3.92.0 and earlier. With a CVSS score of 9.9, this vulnerability permits unauthenticated remote attackers to execute arbitrary code over the network. The vulnerability has been confirmed by the public release of proof-of-concept (PoC) exploit scripts, significantly lowering the barrier for exploitation by malicious actors. Organizations running instances of WordPress with the affected Automatic plugin are at high risk of system compromise, as the vulnerability does not require any user interaction or authenticated privileges. Given the high EPSS score and public availability of exploit tools, immediate remediation is required for all affected installations.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of CVE-2024-27956 allows an attacker to achieve unauthenticated remote code execution on the underlying server. This can lead to full site takeover, data exfiltration of the WordPress database, lateral movement within the hosting environment, and the deployment of persistent backdoors. Given the widespread use of WordPress plugins, this vulnerability presents a high risk to organizations across various sectors utilizing the affected software.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized, concrete actions for detection engineering and security teams:</p>
<ul>
<li>Identify all WordPress installations within the organization using the Valvepress Automatic plugin.</li>
<li>Update the Valvepress Automatic plugin to a version beyond 3.92.0 immediately to mitigate the underlying vulnerability.</li>
<li>Monitor web server access logs for anomalous POST requests directed at plugin-specific endpoints, particularly those originating from unknown or suspicious IP addresses.</li>
<li>Given the public availability of PoC scripts, implement temporary Web Application Firewall (WAF) rules to block suspicious patterns targeting the plugin if patching cannot be performed immediately.</li>
</ul>
]]></content:encoded><category domain="severity">critical</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>rce</category><category>web-application</category></item></channel></rss>