References https://www.acunetix.com/vulnerabilities/web/wordpress-database-credentials-disclosure/ https://hackerone.com/reports/1912671 https://hackerone.com/reports/3252302 https://blog.sucuri.net/2023/07/tips-for-wp-config-how-to-avoid-sensitive-data-exposure.html https://developer.wordpress.org/advanced-administration/security/hardening/ https://medium.com/stolabs/why-should-you-protect-your-wp-config-php-file-d1d1e6c0d6e6 https://wpscan.com/blog/wordpress-configuration-file-backups/ https://melapress.com/secure-wp-config-php-file/ https://monovm.com/blog/hide-wp-config-on-wordpress-site/ https://www.malcare.com/blog/secure-site-with-wp-config/
Related VulnerabilitiesPoCCVE-2026-26265: Discourse - Private User Field Disclosure via Directory Items IDORPoCCVE-2026-27454: Discourse <=2026.2.0 - Hidden Post Revision Disclosure via revert_to Authorization BypassPoCCVE-2026-81199: MasterStudy LMS < 3.7.46 - Unauthenticated Student Statistics DisclosurePoCCVE-2026-87820: CyberPanel 2.4.3-2.4.5 - AI Scanner Debug DisclosurePoCCVE-2017-8225: GoAhead Camera - Credential DisclosurePoCCVE-2026-55229: Gotenberg < 8.34.0 - Local File DisclosureWordpress Events Calendar插件敏感信息泄露漏洞(CVE-2025-9808)WordPress Directory Kit 插件敏感信息泄露漏洞(CVE-2025-13920)PoCCVE-2025-53887: Directus < 11.9.0 - Version DisclosurePoCCVE-2026-42878: FacturaScripts - Unauthenticated phpinfo DisclosurePoCCVE-2025-14998: Branda WordPress plugin - Privilege EscalationPoCCVE-2026-0717: LottieFiles for Gutenberg <= 3.0.0 - Unauthenticated Settings DisclosurePoCCVE-2026-11801: WPAdverts <= 2.3.2 - Information Disclosure