Campaign Monitor for WordPress - Information Disclosure
Campaign Monitor for WordPress plugin for WordPress versions up to 2.8.15 contains a full path disclosure caused by improper access restriction and enabled display_errors in /forms/views/admin/create.php, letting unauthenticated attackers retrieve server paths, exploit requires display_errors to be enabled. References: https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/forms-for-campaign-monitor/campaign-monitor-for-wordpress-2815-unauthenticated-full-path-disclosure https://wordpress.org/plugins/forms-for-campaign-monitor/ https://nvd.nist.gov/vuln/detail/CVE-2024-6569 Remediation: Update to the latest version of the plugin where the issue is fixed, or disable display_errors and restrict access to the affected file.
Used 3.1k times · url