BulletProof Security <= 5.1 - Sensitive Information Disclosure

2021-09-16 15:36
Vincent Rakotomanga

Strategic Overview

Status
Patched in 5.2
Affected PluginBulletProof Security
Affected Version<= 5.1
CVSS5.3Medium
CVECVE-2021-39327
View all BulletProof Security vulnerabilities

Vulnerability Overview

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

Technical Analysis

REMEDIATION: Update to version 5.2, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C