peter bassill · operator
$ cve CVE-2021-39327 JSON

CVE-2021-39327 EXPLOIT

5.3
MEDIUM · CVSS 3.1 · EPSS 71.7% (pctl 99)

Patch early

A public exploit exists.

Description

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

Scoring

CVSS5.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS71.69% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2021-09-17
Last modified2026-06-17

Affected (1)

VendorProduct
ait-probulletproof security

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD