CVE-2024-12542

HIGH

linkID WordPress <0.1.2 - Info Disclosure

Title source: llm

Description

The linkID plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check when including the 'phpinfo' function in all versions up to, and including, 0.1.2. This makes it possible for unauthenticated attackers to read configuration settings and predefined variables on the site's server. The plugin does not need to be activated for the vulnerability to be exploited.

Exploits (3)

github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-12542-PoC
nomisec WORKING POC
by Nxploited · poc
https://github.com/Nxploited/CVE-2024-12542-PoC
nomisec WRITEUP
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-12542

Scores

CVSS v3 8.6
EPSS 0.2262
EPSS Percentile 95.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Classification

CWE
CWE-862
Status draft

Timeline

Published Jan 09, 2025
Tracked Since Feb 18, 2026