CVE-2021-39312
HIGH 7.5EPSS 77.9%
The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.
- CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v3.1
- 7.5 HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 77.94% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- high · CWE-22
- Published
- 2021-12-14
- Updated
- 2025-01-31
Proof-of-concept exploits (2)
- http://packetstormsecurity.com/files/165434/WordPress-The-True-Ranker-2.2.2-Arbitrary-Fil…
- root-wav/wordpress-true-ranker-cve-2021-39312