S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Misconfiguration·Updated Jun 16, 2026

CVE-2024-6569 Scanner

CVE-2024-6569 Scanner - Information Disclosure vulnerability in Campaign Monitor for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.9k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6569
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The Campaign Monitor for WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due the plugin not properly restricting direct access to /forms/views/admin/create.php and display_errors being enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Campaign Monitor for WordPressby vibhorchhabra
0
campaign_monitorby campaignmonitor
0
Updated Sep 10, 2026View on NVD →
Detail

Campaign Monitor for WordPress is a plugin used to integrate the Campaign Monitor's email marketing services with WordPress sites. It is widely used by website administrators and digital marketers to manage subscribers and automate email campaigns directly from WordPress. The plugin's functionality allows users to create and customize signup forms and track email performance metrics. Its integration capability with Campaign Monitor provides a seamless project management experience for various marketing campaigns conducted by businesses and bloggers alike. Nevertheless, vulnerabilities in plugins like these can be detrimental to the security of the platforms they reside on.

The information disclosure vulnerability detected in Campaign Monitor for WordPress arises from improper access restrictions and the enabling of error messages in the admin create.php view. This flaw allows unauthenticated attackers to retrieve server paths, which could assist in further malicious activities targeted at the website. By exploiting this weakness, attackers can gain insights into the file structure and configuration of the server hosting the site. Such exploits often begin with information gathering, making this vulnerability a valuable target for attackers.

The technical aspects of the vulnerability involve triggering processes within the create.php file, where inadequate restrictions coupled with display_errors being enabled lead to path disclosures. The vulnerable endpoint is accessible via HTTP requests to specific paths within the WordPress plugin's directory. Attackers craft requests that result in error states, revealing paths and potentially sensitive configuration information in the response. This path disclosure may subsequently be employed to inform and execute further attacks against the host system.

Exploitation of this information disclosure vulnerability can have significant consequences for the affected site. Malicious actors may gain insights into the server structure, facilitating escalations to more severe attacks such as code execution or file inclusion vulnerabilities. This level of access increases the likelihood of unauthorized data access or administrative control by the attacker. As a result, the integrity and security of the webserver can be compromised, potentially leading to data breaches and service disruptions.

REFERENCES

Solution Advice
  • Update to the latest version of the Campaign Monitor for WordPress plugin where the vulnerability has been addressed.
  • Disable display_errors to prevent leakage of server paths and other error-related information.
  • Restrict access to the vulnerable create.php file to authorized users only.
  • Regularly audit and review plugin configurations to ensure they adhere to security best practices.
  • Implement additional logging and monitoring to detect any unauthorized access attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.