CVE-2024-9935
HIGH NUCLEIPDF Generator Addon - Path Traversal
Title source: llmDescription
The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
Exploits (5)
github
WORKING POC
40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/WordPress(CVE-2024-9935).py
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-9935
Nuclei Templates (1)
PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download
HIGHVERIFIEDby s4e-io
FOFA:
body="wp-content/plugins/pdf-generator-addon-for-elementor-page-builder/"
References (2)
Scores
CVSS v3
7.5
EPSS
0.9362
EPSS Percentile
99.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-22
Status
draft
Timeline
Published
Nov 16, 2024
Tracked Since
Feb 18, 2026