CVE-2024-35776 MEDIUM

CVE-2024-35776: WordPress phpinfo() WP plugin <= 5.0 - Unauthenticated Data Exposure vulnerability

Vendor Exeebit
Product phpinfo() WP
Weakness CWE-200 · Info exposure
Published June 21, 2024
Last update April 28, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Exeebit phpinfo() WP.This issue affects phpinfo() WP: from n/a through 5.0.

Explanation of Vulnerability in Simple Terms

02Summary

The phpinfo() WP product exposes sensitive server and PHP configuration details to unauthenticated visitors. An attacker can access this information over the network without any special privileges or user interaction. The exposed data may include database credentials, API keys, file paths, and other system details that could aid further attacks.

What an attacker can do

03Attacker Capabilities

Read sensitive server configuration and PHP environment details without authentication.

Potential impact on your site

04Site Impact

Attackers can gather reconnaissance data about your server setup, potentially exposing credentials and system paths.

Conditions required to exploit

05Prerequisites

Network access to the affected site; no authentication or user interaction required.

Key dates

06Disclosure timeline

June 21, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE