CVE-2021-39327
The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.
- Affected products
- Bulletproof Security
- Ait-pro Bulletproof Security
- ≤ 5.1
- Fix
- Available
- CVSS 3.1
- 5.3 MEDIUM
- EPSS
- 71.7% (99th percentile)
- Weakness
- CWE-200, CWE-459
- NVD status
- Modified
- Published
- 2021-09-17
Fix
Update to version 5.2 or newer of the plugin.
CVE-2021-39327 at NVD
7 known exploits for CVE-2021-39327
Proof-of-concept code and exploit modules indexed by Sploitus
Exploits
Wordpress BulletProof Security Backup Disclosure
Wordpress BulletProof Security 5.1 Plugin - Sensitive Information Disclosure Vulnerability
Wordpress Plugin BulletProof Security 5.1 - Sensitive Information Disclosure
WordPress BulletProof Security 5.1 Information Disclosure
Wordpress BulletProof Security Backup Disclosure
BulletProof Security < 5.2 - Sensitive Information Disclosure