# CVE-2024-6569: Campaign Monitor For WordPress - Information Disclosure

> Live exploitation tracking for CVE-2024-6569 by the CrowdSec Live Exploit Tracker, built from real-world attack data crowdsourced from CrowdSec's global network.

Page: https://tracker.crowdsec.net/cves/CVE-2024-6569

## Key facts

- **Exploitation phase:** Limited Exploitation. The vulnerability is known but shows very limited attacker interest or exploitation activity.
- **CVSS score:** 5.3
- **Public exploit available:** Yes
- **Affected products:** VibhorChhabra Campaign Monitor For WordPress
- **Weaknesses:** CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'))
- **Tags:** wordpress, cms

## Description

The Campaign Monitor For WordPress plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.8.15. This is due the plugin not properly restricting direct access to /forms/views/admin/create.php and display_errors being enabled. This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be used to aid other attacks. The information displayed is not useful on its own, and requires another vulnerability to be present for damage to an affected website.

## CrowdSec analysis

[CVE-2024-6569](https://euvd.enisa.europa.eu/vulnerability/CVE-2024-6569) is an information disclosure vulnerability in the Campaign Monitor For WordPress plugin, affecting all versions up to 2.8.15. This flaw allows unauthenticated attackers to obtain the full filesystem path of the web application by directly accessing a specific PHP file when display_errors is enabled. While the disclosed information is not immediately dangerous on its own, it can significantly aid attackers in crafting more targeted exploits if other vulnerabilities are present on the affected WordPress site.

CrowdSec has been tracking this vulnerability and its exploits since 24th of June 2026.

CrowdSec network observations suggest that most exploitation of CVE-2024-6569 involves focused reconnaissance to identify viable targets. Attackers typically tailor their campaigns based on system exposure and configuration. It is unlikely that a given attack is accidental.
In addition, according to the CrowdSec network, attack volume against CVE-2024-6569 has dipped slightly compared to the previous week. Although still commonly targeted, the decline suggests a cooling-off period. Long-term relevance remains, but attention is waning.

Attackers probe the endpoint `/wp-content/plugins/forms-for-campaign-monitor/forms/views/admin/create.php` to trigger error messages that disclose full server file paths, exploiting misconfigurations with display_errors enabled.

## Timeline

- 2024-07-27: CVE Published. CVE-2024-6569 is published to NVD.
- 2026-06-24: Rule Released. CrowdSec releases a rule to detect CVE-2024-6569 exploitation attempts against the CrowdSec Network.
- 2026-06-25: CrowdSec First Seen. CrowdSec observes in-the-wild exploitation of CVE-2024-6569 for the first time.

## References

- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-6569.yaml

## Live exploitation data

The [Live Exploit Tracker page](https://tracker.crowdsec.net/cves/CVE-2024-6569) follows observed exploitation activity for CVE-2024-6569. [Request an API key](https://tracker.crowdsec.net/request-api-key) for full access to its exploitation timeline, attacking IP addresses and blocklists.
