CVE-2024-12849 is an arbitrary file-read vulnerability in the Error Log Viewer By WP Guru plugin for WordPress through version 1.0.1.3. The unauthenticated wp_ajax_nopriv_elvwp_log_download AJAX action permits reading arbitrary files from the server. Files accessible to the WordPress process may expose sensitive information.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (CVE-2024-12849.py) and a README.md. The exploit targets the Error Log Viewer By WP Guru WordPress plugin (versions <= 1.0.1.3), which is vulnerable to unauthenticated arbitrary file read via the 'elvwp_log_download' AJAX action. The script allows an attacker to: - Check the plugin version by fetching the readme.txt file from the plugin directory. - Exploit the vulnerability by sending a crafted POST request to /wp-admin/admin-ajax.php, specifying any file path (default: /etc/passwd) to read its contents. - Specifically target and attempt to download the sensitive wp-config.php file if the WordPress installation path is provided. All actions and results are logged to a local data.txt file with timestamps. The README provides usage instructions and describes the vulnerability. The exploit is operational and can be used to extract sensitive files from vulnerable WordPress installations without authentication.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.