CVE-2024-9935

HIGH NUCLEI

PDF Generator Addon - Path Traversal

Title source: llm

Description

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 2.0.0 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. CVE-2025-24569 may be a duplicate of this issue.

Exploits (5)

github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/WordPress(CVE-2024-9935).py
nomisec WORKING POC 7 stars
by verylazytech · poc
https://github.com/verylazytech/CVE-2024-9935
nomisec WORKING POC 2 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-9935
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-9935
nomisec WORKING POC
by Nxploited · poc
https://github.com/Nxploited/CVE-2024-9935

Nuclei Templates (1)

PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download
HIGHVERIFIEDby s4e-io
FOFA: body="wp-content/plugins/pdf-generator-addon-for-elementor-page-builder/"

Scores

CVSS v3 7.5
EPSS 0.9382
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-22
Status published
Products (2)
redefiningtheweb/PDF Generator Addon for Elementor Page Builder < 1.7.5
redefiningtheweb/PDF Generator for WordPress Elementor < 2.0.0
Published Nov 16, 2024
Tracked Since Feb 18, 2026