← Back to browse · API

CVE-2021-39312

Severity
HIGH
CVSS
7.5
EPSS
0.77944
Risk score
57.28
CISA KEV
No
PoC
No
Published
2021-12-14
Modified
2025-01-31
First seen
2026-08-07
Aliases
EUVD-2021-25673, GHSA-2MM8-GJG2-WHMX
Products
optimizza:True Ranker 2.2.2 ≤2.2.2
Sources
euvd EUVD-2021-25673

Description

The True Ranker plugin <= 2.2.2 for WordPress allows arbitrary files, including sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file.

References