CVE-2024-9935

HIGH NUCLEI

PDF Generator Addon - Path Traversal

Title source: llm

Description

The PDF Generator Addon for Elementor Page Builder plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.7.5 via the rtw_pgaepb_dwnld_pdf() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

Exploits (5)

github WORKING POC 40 stars
by iSee857 · pythonpoc
https://github.com/iSee857/CVE-PoC/tree/main/WordPress(CVE-2024-9935).py
nomisec WORKING POC 7 stars
by verylazytech · poc
https://github.com/verylazytech/CVE-2024-9935
nomisec WORKING POC 2 stars
by RandomRobbieBF · poc
https://github.com/RandomRobbieBF/CVE-2024-9935
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2024-9935
nomisec WORKING POC
by Nxploited · poc
https://github.com/Nxploited/CVE-2024-9935

Nuclei Templates (1)

PDF Generator Addon for Elementor Page Builder <= 1.7.5 - Arbitrary File Download
HIGHVERIFIEDby s4e-io
FOFA: body="wp-content/plugins/pdf-generator-addon-for-elementor-page-builder/"

Scores

CVSS v3 7.5
EPSS 0.9362
EPSS Percentile 99.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-22
Status draft

Timeline

Published Nov 16, 2024
Tracked Since Feb 18, 2026