CrowdSecLive Exploit Tracker
Limited ExploitationCVE-2024-6569Public Exploit

Campaign Monitor For WordPress - Information Disclosure (CVE-2024-6569)

PublishedJul 27, 2024
First SeenJun 25, 2026
Last Seen
Reported
CVSS5.3
wordpresscms

Description

The Campaign Monitor For WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due the plugin not properly restricting direct access to /forms/views/admin/create.php and display_errors being enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

psychologyCrowdSec Analysis

CVE-2024-6569 is an information disclosure vulnerability in the Campaign Monitor For WordPress plugin, affecting all versions up to 2.8.15. This flaw allows unauthenticated attackers to obtain the full filesystem path of the web application by directly accessing a specific PHP file when display_errors is enabled. While the disclosed information is not immediately dangerous on its own, it can significantly aid attackers in crafting more targeted exploits if other vulnerabilities are present on the affected WordPress site.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

Data from the CrowdSec community indicates that exploitation of CVE-2024-6569 is highly selective and intelligence-driven. Threat actors use advanced reconnaissance and carefully choose their targets, often as part of sophisticated campaigns or advanced persistent threat operations. CrowdSec network telemetry also shows that exploitation of CVE-2024-6569 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threat landscapes.

Attackers probe the endpoint /wp-content/plugins/forms-for-campaign-monitor/forms/views/admin/create.php to trigger error messages that disclose full server file paths, exploiting misconfigurations with display_errors enabled.

lock

Full Intelligence Available

Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.

EventDate
CVE Published2024-07-27
Rule Released2026-06-24
CrowdSec First Seen2026-06-25

Remediation & Protection

lock to download blocklists, subscribe to firewalls, and access IP intelligence.