漏洞描述
WordPress The Events Calendar plugin is vulnerable to full path disclosure via direct access to plugin files.
id: wp-the-events-calendar-fpd
info:
name: WordPress The Events Calendar - Full Path Disclosure
author: ritikchaddha
severity: low
description: |
WordPress The Events Calendar plugin is vulnerable to full path disclosure via direct access to plugin files.
reference:
- https://wordpress.org/plugins/the-events-calendar/
metadata:
verified: true
max-request: 3
vendor: developer
product: the-events-calendar
framework: wordpress
fofa-query: body="/wp-content/plugins/the-events-calendar/"
tags: wp,wordpress,wp-plugin,fpd,events-calendar,exposure
http:
- method: GET
path:
- "{{BaseURL}}/wp-content/plugins/the-events-calendar/src/Tribe/Main.php"
- "{{BaseURL}}/wp-content/plugins/the-events-calendar/src/Tribe/Admin/Admin.php"
- "{{BaseURL}}/wp-content/plugins/the-events-calendar/common/src/Tribe/Main.php"
stop-at-first-match: true
matchers:
- type: dsl
dsl:
- 'status_code == 200'
- 'contains_all(body, "Fatal error", "the-events-calendar", "Uncaught Error:")'
condition: and
# digest: 4a0a0047304502202f80aa3fd713cf847de6f1e5b4319d494724ed79d15149de8fedf7676d5a8408022100954b72f4cd3a57eddc0046b6c01c7569704bb0391e66f379bfd57afad55ac9fe:922c64590222798bb761d5b6d8e72950