Vulnerabilities protected by our Directory Traversal (Requesting wp-config.php) firewall rule

727,522
Attacks Blocked in Past 24 Hours

Showing 41-60 of 225 Vulnerabilities

Title CVE ID CVSS Vector Date
Backup and Restore plugin – WordPress <= 1.0.3 - Authenticated (Admin+) Arbitrary File Deletion 5.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H November 8, 2021
Contact Forms - Drag & Drop Contact Form Builder <= 1.0.5 - Authenticated (Admin+) Arbitrary System File Read CVE-2021-24689 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N September 27, 2021
Simple Download Monitor <= 3.9.4 - Contributor+ Arbitrary File Download CVE-2021-24692 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N September 2, 2021
ZoomSounds - WordPress Wave Audio Player with Playlist <= 6.45 - Directory Traversal CVE-2021-39316 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N August 30, 2021
OMGF <= 4.5.3 - Unauthenticated Path Traversal in REST API CVE-2021-24638 9.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H August 23, 2021
AceIDE <= 2.6.2 - Authenticated (Admin+) Arbitrary File Read CVE-2021-24549 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N July 24, 2021
Photo Gallery <= 1.5.74 - File Upload Path Traversal CVE-2021-24363 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N July 18, 2021
Haxcan <= 1.0.0 - Authenticated (Admin+) Path Traversal to Arbitrary File Read 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N July 5, 2021
WP Fastest Cache <= 0.9.1.6 - Authenticated (Admin+) Directory Traversal to Arbitrary File Deletion CVE-2021-20714 6.5 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H April 27, 2021
Media File Organizer <= 1.0.1 - Directory Traversal CVE-2020-24144 8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N April 13, 2021
Video Downloader for TikTok < 1.4 - Directory Traversal CVE-2020-24143 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N April 13, 2021
CM Download Manager < 2.8.0 - Directory Traversal to Arbitrary File Deletion and Denial of Service CVE-2020-24146 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H April 13, 2021
Theme Editor <= 2.5 - Authenticated Arbitrary File Download CVE-2021-24154 4.9 CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N February 13, 2021
Product Input Fields for WooCommerce <= 1.2.6 - Missing Authorization CVE-2020-36696 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N August 3, 2020
Adning Advertising <= 1.5.5 - Unauthenticated Arbitrary File Deletion via Path Traversal CVE-2020-36728 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N July 7, 2020
Simple File List <= 4.2.7 - Arbitrary File Deletion CVE-2020-12832 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L May 16, 2020
WordPress File Upload <= 4.12.2 - Directory Traversal to Remote Code Execution CVE-2020-10564 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H March 13, 2020
Duplicator < 1.3.28 - Directory Traversal CVE-2020-11738 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N February 28, 2020
ARforms <= 3.7.1 - Unauthenticated Arbitrary File Deletion CVE-2019-16902 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N October 11, 2019
Advanced Access Manager <= 5.9.8.1 - Unauthenticated Arbitrary File Read CVE-2019-25213 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H September 9, 2019

Did you know Wordfence Intelligence provides free personal and commercial API access to our comprehensive WordPress vulnerability database, along with a free webhook integration to stay on top of the latest vulnerabilities added and updated in the database? Get started today!

Learn more

Want to get notified of the latest vulnerabilities that may affect your WordPress site?
Install Wordfence on your site today to get notified immediately if your site is affected by a vulnerability that has been added to our database.

Get Wordfence

The Wordfence Intelligence WordPress vulnerability database is completely free to access and query via API. Please review the documentation on how to access and consume the vulnerability data via API.

Documentation