CVE-2024-12558 is a vulnerability in the WP BASE Booking of Appointments, Services and Events WordPress plugin (versions up to and including 4.9.2) where the export_db function lacks a proper capability check. This allows authenticated users with Subscriber-level access or higher to invoke the function and export sensitive database information, including hashed administrator passwords.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (CVE-2024-12558.py) and a README.md. The exploit targets the WP BASE Booking of Appointments, Services and Events WordPress plugin (versions 4.9.2 and below), which is vulnerable due to a missing capability check on the export_db function. The script first checks for the presence and version of the plugin, then logs in as a provided WordPress user (Subscriber or higher), and finally sends a crafted POST request to /wp-admin/admin-ajax.php to trigger a database export. The resulting data, which may include sensitive information such as hashed administrator passwords, is saved to a local file. The README provides usage instructions and example output. The exploit is operational and requires valid credentials for a low-privilege user on the target WordPress site.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.