CVE-2024-52476
📛 CVE Title
WordPress Fediverse Embeds plugin <= 1.5.3 - Arbitrary File Upload vulnerability
Description
Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell to a Web Server.This issue affects Fediverse Embeds: from n/a through <= 1.5.3.
Overview
- State
- PUBLISHED
- Assigner (CNA)
- Patchstack
- CVSS severity
- CRITICAL
- CVSS score
- 10.0 / 10
- CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Effective score
- 10.0 / 10 CRITICAL source: CNA overview
- CWE(s)
-
CWE-434 - Reserved
- 2024-11-11
- Published
- 2024-12-02 14:48 UTC
- Last updated
- 2026-04-28 18:10 UTC
- Source
- https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2024/52xxx/CVE-2024-52476.json
- Linked Threat
- CVE-2024-52476 — Fediverse Embeds <= 1.5.3 - Unauthenticated Arbitrary File Upload
NVD triage scoring NVD CVE 2.0
Layer NVD adds on top of the CNA's CVE record — published / last-modified timestamps, exploitability / impact subscores, and the FIRST.org EPSS probability that this CVE will be exploited in the wild in the next 30 days.
- NVD published
- 2024-12-02 14:15:09 UTC
- NVD last modified
- 2026-06-17 08:07:18 UTC
- NVD CVSS v3.1
- 10.0 / 10 CRITICAL source: audit@patchstack.com
- NVD CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Exploitability subscore
- 3.9 / 10
- Impact subscore
- 6.0 / 10
- EPSS score
- 0.0053 (probability of exploitation in next 30 days)
- EPSS percentile
- 42.08% vs all CVEs — higher = more likely to be exploited, as of 2026-08-14
NVD / KEV / EPSS data refreshed 2026-08-15 00:13 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.
European Union Vulnerability Database ENISA EUVD
ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.
- EUVD ID
-
EUVD-2024-46135 - Assigner
- Patchstack
- Published
- Dec 2, 2024, 1:48:59 PM
- Updated
- Apr 28, 2026, 4:10:43 PM
- EUVD base score (CVSS 3.1)
-
10.0 / 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EUVD-reported EPSS
- 0.4900
- Vendors
- stefanbohacek, Stefan Bohacek
- Products
-
Fediverse Embeds (n/a ≤1.5.3)Fediverse Embeds (0 ≤1.5.3)
- Aliases
-
GHSA-6vjf-5pvr-cw5f
ENISA description: Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell to a Web Server.This issue affects Fediverse Embeds: from n/a through <= 1.5.3.
Affected products (1)
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Stefan Bohacek | Fediverse Embeds |
0 (affected)
|
— |
Vendor references (1)
References embedded in the original CVE record by the assigning CNA.
Web references (5)
DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.
- http://cwe.mitre.org/data/definitions/434.html rapid7:cwe.mitre.org
- https://attackerkb.com/topics/CVE-2024-52476 rapid7:attackerkb.com
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-46135 rapid7:euvd.enisa.europa.eu
- https://www.cve.org/CVERecord?id=CVE-2024-52476 rapid7:www.cve.org
- https://www.wordfence.com/threat-intel/vulnerabilities/id/facba004-fc2a-4ba0-aabf-551b5f11e567?source=api-prod rapid7:www.wordfence.com
NVD-tagged references (1)
Reference list NVD curates from the CNA record, vendor advisories, and third-party reports. The tag chips below are NVD's analyst-assigned categories.
Indicators (2)
IOCs linked to the auto-promoted Threat row.
| Type | Value | VirusTotal | Attached |
|---|---|---|---|
| domain |
server.this
|
no local data | 2026-05-18 21:19 UTC |
| cve |
CVE-2024-52476
|
no local data | 2026-06-06 14:13 UTC |
Remediations (22)
Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.
-
web:support.microsoft.com
Improvements and fixes This security update introduces the SharePoint Server Subscription Edition Version 26H1 feature update. This feature update will be included in all SharePoint Server Subscription Edition public updates going forward. For more information about this feature update, see New and improved features in SharePoint Server Subscription Edition Version 26H1. This link may be ...
2026-08-07 14:47 UTC -
web:www.oracle.com
This Critical Security Patch Update contains 35 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Security Patch Update and other Oracle Software Security Assurance activities is located at May 2026 Critical Security Patch Update: Executive Summary and Analysis.
2026-08-07 14:47 UTC -
web:www.nist.gov
NIST maintains the National Vulnerability Database (NVD), a repository of information on software and hardware flaws that can compromise computer security. This is a key piece of the nation's cybersecurity infrastructure.
2026-08-07 14:47 UTC -
web:www.cisa.gov
The median time for full resolution rose to 43 days. Defenders need greater clarity and speed to patch systems in today's threat landscape. We must flip the script on patching prioritization: patch smarter, not harder.
2026-08-07 14:47 UTC -
web:techcommunity.microsoft.com
We wanted to tell you how to address the Exchange Server May 2026 vulnerability CVE -2026-42897.
2026-08-07 14:47 UTC -
Wordfence remediation: Fediverse EmbedsWordfence
Update to version 1.5.4, or a newer patched version
2026-06-06 14:13 UTC -
web:www.oracle.com
This Critical Patch Update contains 481 new security patches across the product families listed below. Please note that an MOS note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at April 2026 Critical Patch Update: Executive Summary and Analysis.
2026-05-22 10:48 UTC -
web:overwatch.blizzard.com
Overwatch Retail Patch Notes - April 23, 2026 Balance Hotfix Update This is a balance hotfix update. Replay codes from the April 14, 2026 patch and onwards are still available.
2026-05-22 10:48 UTC -
web:www.esri.com
Key highlights The ArcGIS Server Security 2025 update 2 is available This patch resolves 10 Medium severity vulnerabilities This security patch is cumulative, and includes fixes provided in the ArcGIS Server Security 2025 update 1.
2026-05-22 10:48 UTC -
web:support.servicenow.com
Overview The advisories below document publicly disclosed Common Vulnerabilities and Exposures ( CVEs ) in the Now Platform by ServiceNow. Because ServiceNow uses various methods to communicate vulnerability information, patches, and other fixes, customers should review family, security patch , and hotfix release notes, which are available at https://docs.servicenow.com, for a complete list of ...
2026-05-22 10:48 UTC -
web:portal.msrc.microsoft.com
The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.
2026-05-22 10:48 UTC -
web:blog.qualys.com
May 2026's Patch Tuesday arrives with Microsoft addressing a fresh set of vulnerabilities across its ecosystem, reinforcing the ongoing need for timely patching in an increasingly threat-heavy…
2026-05-22 10:48 UTC -
web:blogs.oracle.com
For more information about the Critical Patch Update program, see the security vulnerability remediation practices page located on the Oracle Trust Center.
2026-05-22 02:49 UTC -
web:www.tenable.com
Oracle addresses 241 CVEs in its April Critical Patch Update, the second quarterly update of 2026 with 481 patches, including 34 critical updates.
2026-05-22 02:49 UTC -
web:www.windowslatest.com
Windows 11 April 2026 update adds Narrator Copilot support, faster Settings, File Explorer fixes, and key security improvements.
2026-05-22 02:49 UTC -
web:zecurit.com
Get the complete breakdown of Microsoft's May 2026 Patch Tuesday. We analyze the latest security updates and all critical CVEs .
2026-05-22 02:49 UTC -
web:cyberwebspider.com
Oracle has issued a substantial update, releasing 481 security patches as part of its April 2026 Critical Patch Update (CPU). This comprehensive update spans 28 product families and addresses over 300 vulnerabilities that could be exploited remotely without the need for authentication.
2026-05-22 02:49 UTC -
web:msrc.microsoft.com
The Microsoft Security Response Center (MSRC) investigates all reports of security vulnerabilities affecting Microsoft products and services, and provides the information here as part of the ongoing effort to help you manage security risks and help keep your systems protected.
2026-05-22 02:49 UTC -
web:layerlogix.com
April 2026 Patch Tuesday drops today. Here's what's critical, what to patch first, and how Houston IT teams should handle deployment — including the Secure Boot certificate deadline reminder.
2026-05-22 02:49 UTC -
web:krebsonsecurity.com
Microsoft expects that exploitation is more likely. May's Patch Tuesday is a welcome respite from April, which saw Microsoft fix a near-record 167 security flaws.
2026-05-22 02:49 UTC -
web:nvd.nist.gov
An official website of the United States government Here's how you know
2026-05-22 02:49 UTC -
web:www.notebookcheck.net
Microsoft's Windows 11 KB5083769 April 2026 update causes critical boot failures, pixelated BSODs, and BitLocker recovery loops on Windows 11 24H2 and 25H2 PCs.
2026-05-22 02:49 UTC
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.
Raw JSON
The full cvelistV5 record. Download as CVE-2024-52476.json.
{
"containers": {
"adp": [
{
"affected": [
{
"cpes": [
"cpe:2.3:a:stefanbohacek:fediverse_embeds:*:*:*:*:*:*:*:*"
],
"defaultStatus": "unknown",
"product": "fediverse_embeds",
"vendor": "stefanbohacek",
"versions": [
{
"lessThanOrEqual": "1.5.3",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"metrics": [
{
"other": {
"content": {
"id": "CVE-2024-52476",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "total"
}
],
"role": "CISA Coordinator",
"timestamp": "2024-12-02T19:14:09.387363Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2024-12-02T19:15:44.145Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"collectionURL": "https://wordpress.org/plugins",
"defaultStatus": "unaffected",
"packageName": "fediverse-embeds",
"product": "Fediverse Embeds",
"vendor": "Stefan Bohacek",
"versions": [
{
"changes": [
{
"at": "1.5.4",
"status": "unaffected"
}
],
"lessThanOrEqual": "1.5.3",
"status": "affected",
"version": "0",
"versionType": "custom"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "finder",
"value": "stealthcopter | Patchstack Bug Bounty Program"
}
],
"datePublic": "2026-04-01T16:29:57.725Z",
"descriptions": [
{
"lang": "en",
"supportingMedia": [
{
"base64": false,
"type": "text/html",
"value": "Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell to a Web Server.<p>This issue affects Fediverse Embeds: from n/a through <= 1.5.3.</p>"
}
],
"value": "Unrestricted Upload of File with Dangerous Type vulnerability in Stefan Bohacek Fediverse Embeds fediverse-embeds allows Upload a Web Shell to a Web Server.This issue affects Fediverse Embeds: from n/a through <= 1.5.3."
}
],
"impacts": [
{
"capecId": "CAPEC-650",
"descriptions": [
{
"lang": "en",
"value": "Upload a Web Shell to a Web Server"
}
]
}
],
"metrics": [
{
"cvssV3_1": {
"attackComplexity": "LOW",
"attackVector": "NETWORK",
"availabilityImpact": "HIGH",
"baseScore": 10,
"baseSeverity": "CRITICAL",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"privilegesRequired": "NONE",
"scope": "CHANGED",
"userInteraction": "NONE",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H",
"version": "3.1"
},
"format": "CVSS",
"scenarios": [
{
"lang": "en",
"value": "GENERAL"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-434",
"description": "Unrestricted Upload of File with Dangerous Type",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-04-28T16:10:43.265Z",
"orgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"shortName": "Patchstack"
},
"references": [
{
"tags": [
"vdb-entry"
],
"url": "https://patchstack.com/database/Wordpress/Plugin/fediverse-embeds/vulnerability/wordpress-fediverse-embeds-plugin-1-5-3-arbitrary-file-upload-vulnerability?_s_id=cve"
}
],
"title": "WordPress Fediverse Embeds plugin <= 1.5.3 - Arbitrary File Upload vulnerability"
}
},
"cveMetadata": {
"assignerOrgId": "21595511-bba5-4825-b968-b78d1f9984a3",
"assignerShortName": "Patchstack",
"cveId": "CVE-2024-52476",
"datePublished": "2024-12-02T13:48:59.926Z",
"dateReserved": "2024-11-11T06:40:17.791Z",
"dateUpdated": "2026-04-28T16:10:43.265Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}