CVE-2021-39327
MEDIUM NUCLEIWordpress BulletProof Security Backup Disclosure
Title source: metasploitExploitation Summary
EIP tracks 2 public exploits for CVE-2021-39327.
PoCs published by Ron Jost, Ron Jost (Hacker5preme), h00die, including Metasploit module auxiliary/scanner/http/wp_bulletproofsecurity_backups.
A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit targets a sensitive information disclosure vulnerability in the BulletProof Security WordPress plugin (versions <= 5.1). It retrieves the contents of a publicly accessible log file (`db_backup_log.txt`) that discloses file paths and database backup locations.
Description
The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.
Exploits (2)
This exploit targets a sensitive information disclosure vulnerability in the BulletProof Security WordPress plugin (versions <= 5.1). It retrieves the contents of a publicly accessible log file (`db_backup_log.txt`) that discloses file paths and database backup locations.
This Metasploit module exploits an information disclosure vulnerability in WordPress BulletProof Security plugin versions <= 5.1. It retrieves publicly accessible backup logs to locate and download database backups, then extracts user credentials from the SQL dump.
Nuclei Templates (1)
References (5)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N