← Back to browse · API

CVE-2021-39327

Severity
MEDIUM
CVSS
5.3
EPSS
0.71688
Risk score
46.29
CISA KEV
No
PoC
No
Published
2021-09-17
Modified
2025-03-31
First seen
2026-08-07
Aliases
EUVD-2021-25688, GHSA-6QG5-VF7X-4FM3
Products
AITpro:BulletProof Security 5.1 ≤5.1
Sources
euvd EUVD-2021-25688

Description

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

References