Sploitus

Exploit for Missing Authorization in Xlplugins Finale

githubexploit Β· 2025-03-12

Exploit Code

README20 lines
## https://sploitus.com/exploit?id=C7A3EB6A-D50F-5FA8-9109-A5281412E709
# CVE-2024-30485 Exploit

## πŸ“Œ Overview

**CVE-2024-30485** is a high-severity vulnerability found in the **Finale Lite** plugin for WordPress (versions Unpacking the package…
Installing the plugin…
Plugin installed successfully.
{"success":true,"data":"Plugin installed and activated successfully!"}
```

## ⚠️ Disclaimer

This script is for **educational and security research purposes only**. Unauthorized testing against systems **without permission** is illegal. Use responsibly.

## πŸ”— References
- [Official CVE Record](https://vulners.com/cve/CVE-2024-30485)
- [WordPress Plugin Page](https://wordpress.org/plugins/finale-woocommerce-sales-countdown-timer-discount/)

*By: Khaled Alenazi (Nxploit)*