On this page
Atomicorp WAF Rule 382238
Rule Summary
- Rule ID: 382238
- Status: Active
- Alert message: Atomicorp.com WAF Rules - Virtual Just In Time Patch: PHP file execution in uploads directory denied
- Observed CWEs: CWE-22 (1), CWE-98 (1), CWE-306 (1), CWE-352 (1), CWE-434 (16), CWE-862 (1)
- Revision: 2
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request filename
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Virtual Just In Time Patch: PHP file execution in uploads directory denied” in the request filename. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2024-56064 | WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCE | indeed-wp-superbackup | 10.0 (v3.1) | Critical |
| CVE-2025-47577 | TI WooCommerce Wishlist <= 2.9.2 - Arbitrary File Upload | ti-woocommerce-wishlist | 10.0 (v3.1) | Critical |
| CVE-2016-15042 | WordPress Frontend File Manager < 4.0 & N-Media Post Frontend < 1.1 - Arbitrary File Upload | frontend file manager | 9.8 (v3.1) | Critical |
| CVE-2020-12832 | WordPress Simple File List - Path Traversal | Simple File List WordPress Plugin | 9.8 (v3.1) | Critical |
| CVE-2021-24212 | WooCommerce Help Scout - Arbitrary File Upload | help scout | 9.8 (v3.1) | Critical |
| CVE-2021-24284 | WordPress Kaswara Modern VC Addons <=3.0.1 - Arbitrary File Upload | kaswara | 9.8 (v3.1) | Critical |
| CVE-2021-24499 | WordPress Workreap - Remote Code Execution | workreap | 9.8 (v3.1) | Critical |
| CVE-2021-34624 | WordPress ProfilePress 3.0-3.1.3 - Arbitrary File Upload | profilepress | 9.8 (v3.1) | Critical |
| CVE-2022-1574 | WordPress HTML2WP <=1.0.0 - Arbitrary File Upload | html2wp | 9.8 (v3.1) | Critical |
| CVE-2022-1952 | WordPress eaSYNC Booking <1.1.16 - Arbitrary File Upload | free booking plugin for hotels, restaurant and car rental | 9.8 (v3.1) | Critical |
| CVE-2022-3982 | WordPress Booking Calendar <3.2.2 - Arbitrary File Upload | booking calendar | 9.8 (v3.1) | Critical |
| CVE-2022-4328 | WooCommerce Checkout Field Manager < 18.0 - Arbitrary File Upload | woocommerce checkout field manager | 9.8 (v3.1) | Critical |
| CVE-2023-51409 | Jordy Meow AI Engine - Unrestricted File Upload | ai engine | 9.8 (v3.1) | Critical |
| CVE-2023-5360 | WordPress Royal Elementor Addons Plugin <= 1.3.78 - Arbitrary File Upload | royal elementor addons | 9.8 (v3.1) | Critical |
| CVE-2024-4620 | ArForms < 6.6 - Remote Code Execution | arforms | 9.8 (v3.1) | Critical |
| CVE-2024-8425 | WooCommerce Ultimate Gift Card ≤ 2.6.0 - Arbitrary File Upload | woocommerce ultimate gift card | 9.8 (v3.1) | Critical |
| CVE-2025-34085 | WordPress Simple File List <=4.2.2 - Remote Code Execution | - | 9.8 | Critical |
| CVE-2025-6058 | WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload | wpbookit | 9.8 (v3.1) | Critical |
| CVE-2026-0740 | Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Upload | ninja forms file uploads | 9.8 (v3.1) | Critical |
| CVE-2021-25094 | Wordpress Tatsubuilder <= 3.3.11 - Remote Code Execution | tatsu | 8.1 (v3.1) | High |
| CVE-2025-48157 | WordPress Formality Plugin <= 1.5.9 - Local File Inclusion | Formality | 8.1 (v3.1) | High |
| CVE-2026-5718 | Drag and Drop Multiple File Upload - CF7 <= 1.3.9.6 - Remote Code Execution | drag-and-drop-multiple-file-upload-contact-form-7 | 8.1 (v3.1) | High |
| CVE-2021-24145 | WordPress Modern Events Calendar Lite <5.16.5 - Authenticated Arbitrary File Upload | modern events calendar lite | 7.2 (v3.1) | High |
| CVE-2026-13158 | Everest Toolkit <= 1.2.3 - Admin+ Arbitrary File Upload | Everest Toolkit | 7.2 (v3.1) | High |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.