Campaign Monitor For WordPress - Information Disclosure (CVE-2024-6569)
Description
The Campaign Monitor For WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due the plugin not properly restricting direct access to /forms/views/admin/create.php and display_errors being enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.
psychologyCrowdSec Analysis
CVE-2024-6569 is an information disclosure vulnerability in the Campaign Monitor For WordPress plugin, affecting all versions up to 2.8.15. This flaw allows unauthenticated attackers to obtain the full filesystem path of the web application by directly accessing a specific PHP file when display_errors is enabled. While the disclosed information is not immediately dangerous on its own, it can significantly aid attackers in crafting more targeted exploits if other vulnerabilities are present on the affected WordPress site.
CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.
Data from the CrowdSec community indicates that exploitation of CVE-2024-6569 is highly selective and intelligence-driven. Threat actors use advanced reconnaissance and carefully choose their targets, often as part of sophisticated campaigns or advanced persistent threat operations. CrowdSec network telemetry also shows that exploitation of CVE-2024-6569 has significantly declined over the past week. Attack volumes are well below the long-term average, suggesting attackers are rapidly losing interest. The vulnerability appears to be falling out of active use across most threat landscapes.
Attackers probe the endpoint /wp-content/plugins/forms-for-campaign-monitor/forms/views/admin/create.php to trigger error messages that disclose full server file paths, exploiting misconfigurations with display_errors enabled.
Full Intelligence Available
Connect your API key to access CrowdSec scores, exploit timelines, and attacker IPs.
| Event | Date |
|---|---|
| CVE Published | 2024-07-27 |
| Rule Released | 2026-06-24 |
| CrowdSec First Seen | 2026-06-25 |