CVE-2021-39312
high · 7.5A public exploit / detection template exists
Weaponised detection is publicly available, which meaningfully raises real-world risk regardless of CVSS. nuclei-templates →
The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.
7.5
CVSS
77.9%
EPSS (exploit prob.)
100th
EPSS percentile
2021-12-14
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Weaknesses
CWE-22
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| trueranker | true_ranker | <= 2.2.2 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/165434/WordPress-The-True-Ranker-2.2.2-Arbitrary-File-Read.html
- https://plugins.trac.wordpress.org/browser/seo-local-rank/tags/2.2.2/admin/vendor/datatables/examples/resources/examples.php
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39312
- http://packetstormsecurity.com/files/165434/WordPress-The-True-Ranker-2.2.2-Arbitrary-File-Read.html
- https://plugins.trac.wordpress.org/browser/seo-local-rank/tags/2.2.2/admin/vendor/datatables/examples/resources/examples.php
- https://www.wordfence.com/vulnerability-advisories/#CVE-2021-39312
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2021-39312