← Back to browse · API

CVE-2024-12849

Severity
HIGH
CVSS
7.5
EPSS
0.46858
Risk score
46.4
CISA KEV
No
PoC
No
Published
2025-01-07
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2024-51150, GHSA-899P-F2MF-G895
Products
wpguruin:Error Log Viewer By WP Guru 0 ≤1.0.1.3
Sources
euvd EUVD-2024-51150

Description

The Error Log Viewer By WP Guru plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 1.0.1.3 via the wp_ajax_nopriv_elvwp_log_download AJAX action. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.

References