CVE-2021-39327

MEDIUM NUCLEI

Wordpress BulletProof Security Backup Disclosure

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2021-39327. PoCs published by Ron Jost, Ron Jost (Hacker5preme), h00die, including Metasploit module auxiliary/scanner/http/wp_bulletproofsecurity_backups. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit targets a sensitive information disclosure vulnerability in the BulletProof Security WordPress plugin (versions <= 5.1). It retrieves the contents of a publicly accessible log file (`db_backup_log.txt`) that discloses file paths and database backup locations.

Description

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

Exploits (2)

exploitdb WORKING POC
by Ron Jost · pythonwebappsphp
https://www.exploit-db.com/exploits/50382

This exploit targets a sensitive information disclosure vulnerability in the BulletProof Security WordPress plugin (versions <= 5.1). It retrieves the contents of a publicly accessible log file (`db_backup_log.txt`) that discloses file paths and database backup locations.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin BulletProof Security <= 5.1
No auth needed
Prerequisites: Target must have the vulnerable plugin installed and accessible · The log file must be publicly accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC
by Ron Jost (Hacker5preme), h00die · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/wp_bulletproofsecurity_backups.rb

This Metasploit module exploits an information disclosure vulnerability in WordPress BulletProof Security plugin versions <= 5.1. It retrieves publicly accessible backup logs to locate and download database backups, then extracts user credentials from the SQL dump.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: WordPress BulletProof Security plugin <= 5.1
No auth needed
Prerequisites: Target must have backup functionality enabled · Backup logs must be publicly accessible
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

WordPress BulletProof Security 5.1 Information Disclosure
MEDIUMby geeknik

Scores

CVSS v3 5.3
EPSS 0.7233
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-200 CWE-459
Status published
Products (1)
ait-pro/bulletproof_security < 5.1
Published Sep 17, 2021
Tracked Since Feb 18, 2026