CVE-2024-12849

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 7, 2025
CWE ID 22

Summary

CVE-2024-12849 is a vulnerability affecting the Error Log Viewer By WP Guru plugin for WordPress. In all versions up to 1.0.1.3, an Arbitrary File Read vulnerability exists, which can be exploited via the wp_ajax_nopriv_elvwp_log_download AJAX action. Unauthenticated attackers can leverage this flaw to read the contents of arbitrary files on the server, potentially gaining access to sensitive information. This vulnerability poses a significant risk to WordPress websites using the Error Log Viewer By WP Guru plugin and requires immediate attention and patching.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share