CVE-2021-39327
BulletProof Security <= 5.1 Sensitive Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
-Decision
Descriptions
The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.
El plugin BulletProof Security de WordPress es vulnerable a una divulgación de información confidencial debido a una divulgación de la ruta de archivos en el archivo ~/db_backup_log.txt de acceso público que otorga a los atacantes la ruta completa del sitio, además de la ruta de los archivos de copia de seguridad de la base de datos. Esto afecta a las versiones hasta la 5.1, incluyéndola
The Wordpress plugin BulletProof Security, versions less than or equal to 5.1, suffers from an information disclosure vulnerability, in that the db_backup_log.txt is publicly accessible. If the backup functionality is being utilized, this file will disclose where the backup files can be downloaded. After downloading the backup file, it will be parsed to grab all user credentials.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-08-20 CVE Reserved
- 2021-09-16 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- 2024-10-20 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
- CWE-459: Incomplete Cleanup
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39327 | Third Party Advisory | |
https://github.com/Hacker5preme/Exploits/blob/main/Wordpress/CVE-2021-39327/README.md |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ait-pro Search vendor "Ait-pro" | Bulletproof Security Search vendor "Ait-pro" for product "Bulletproof Security" | <= 5.1 Search vendor "Ait-pro" for product "Bulletproof Security" and version " <= 5.1" | wordpress |
Affected
|