CVE-2024-12542 is a vulnerability in the linkID plugin for WordPress, affecting all versions up to and including 0.1.2. The vulnerability arises from a missing capability check when including the 'phpinfo' function, allowing unauthenticated attackers to access sensitive server configuration settings and predefined variables. Notably, the plugin does not need to be activated for exploitation to occur.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python proof-of-concept exploit for CVE-2024-12542, targeting the linkID plugin for WordPress (versions 0.1.2 and below). The exploit checks the version of the plugin by fetching the readme.txt file from the target site. If the version is vulnerable, it accesses a specific PHP file within the plugin that exposes the output of phpinfo() due to missing authorization checks. The script saves the PHP configuration output to a local file (phpinfo.php) and logs all actions to output.txt. The repository consists of the main exploit script (CVE-2024-12542.py) and a README.md that explains the vulnerability and usage. The exploit is network-based, requires only the target URL, and does not require authentication or plugin activation on the target. No fake or destructive actions are present; the exploit is focused on information disclosure.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.