Exploitation Summary
EIP tracks 3 public exploits for CVE-2024-12542. PoCs published by Boshe99, Nxploited, RandomRobbieBF.
AI-analyzed exploit summary The repository contains functional exploit code for CVE-2024-12542, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the ability to upload a malicious file to a vulnerable target.
Description
The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.
Exploits (3)
The repository contains functional exploit code for CVE-2024-12542, targeting a WordPress plugin (3DPrint Lite 1.9.1.4) with an arbitrary file upload vulnerability. The Python script demonstrates the ability to upload a malicious file to a vulnerable target.
The repository contains a functional Python script that exploits CVE-2024-12542, an unauthorized access vulnerability in the WordPress 'linkID' plugin (versions up to 0.1.2). The script checks the plugin version and fetches sensitive PHP configuration information via an unauthenticated endpoint.
The repository provides a detailed technical description of CVE-2024-12542, an unauthorized information exposure vulnerability in the linkID WordPress plugin (versions up to 0.1.2). It includes the vulnerable endpoint path and explains the lack of capability checks, but does not contain functional exploit code.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N