Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-9935 — AI Deep Analysis Summary

CVSS 7.5 · High

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: Path Traversal in 'PDF Generator Addon for Elementor'. 💥 **Consequences**: Attackers can read **arbitrary files** on the server. 📄 **Impact**: Sensitive data exposure (config files, source code). 🔓 **Sever…

Q2Root Cause? (CWE/Flaw)

🛡️ **CWE**: CWE-22 (Path Traversal). 🐛 **Flaw**: The `rtw_pgaepb_dwnld_pdf()` function fails to sanitize input. 🔍 **Root Cause**: Unchecked user-supplied file paths allow `../` sequences to escape the intended directory.

Q3Who is affected? (Versions/Components)

🏢 **Vendor**: Redefiningtheweb. 📦 **Product**: PDF Generator for WordPress Elementor. 📉 **Affected**: Versions **1.7.5 and earlier**. ✅ **Fixed**: Version 1.7.6+ (implied by 'up to 1.7.5').

Q4What can hackers do? (Privileges/Data)

🕵️ **Privileges**: **Unauthenticated**. No login needed. 📂 **Data Access**: Read **any file** accessible by the web server. 🔑 **Risk**: Extract database credentials, `.env` files, or core WordPress code. 💣 **Lateral Move…

Q5Is exploitation threshold high? (Auth/Config)

📉 **Threshold**: **LOW**. 🔓 **Auth**: None required (Unauthenticated). ⚙️ **Config**: Default installation is vulnerable. 🌐 **Network**: Remote exploitation over HTTP/HTTPS. 🎯 **Ease**: Simple GET request with crafted pa…

Q6Is there a public Exp? (PoC/Wild Exploitation)

🔥 **Public Exploits**: **YES**. 📂 **PoCs**: Available on GitHub (RandomRobbieBF, verylazytech, Nxploited). 🤖 **Automated**: Nuclei templates exist for mass scanning. 🚀 **Status**: Active exploitation is trivial.

Q7How to self-check? (Features/Scanning)

🔍 **Check**: Send GET request to `/?rtw_generate_pdf=true&rtw_pdf_file=../../../etc/passwd`. 📡 **Scan**: Use Nuclei template `CVE-2024-9935.yaml`. 👀 **Visual**: If server returns file content, you are vulnerable. 🛠️ **To…

Q8Is it fixed officially? (Patch/Mitigation)

🔧 **Patch**: Update plugin to **version 1.7.6 or later**. 📥 **Source**: WordPress Plugin Repository or Vendor site. 🔄 **Action**: Immediate update recommended. 📝 **Note**: Check changelog for confirmation of fix in `clas…

Q9What if no patch? (Workaround)

🚫 **No Patch?**: Disable the plugin immediately. 🛡️ **WAF**: Block requests containing `rtw_generate_pdf=true` and `rtw_pdf_file`. 🔒 **Access Control**: Restrict access to `/elementor-84/` endpoint. 🧹 **Cleanup**: Remove…

Q10Is it urgent? (Priority Suggestion)

⚡ **Urgency**: **HIGH**. 🚨 **Priority**: Patch immediately. 📉 **Risk**: Unauthenticated + File Read = Critical Data Breach. 📢 **Action**: Alert users, force updates, monitor for exploitation.