
Exploit-WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read
Python proof-of-concept for CVE-2021-39312, affecting The True Ranker (seo-local-rank) WordPress plugin versions ≤ 2.2.2.
The vulnerability allows an attacker to read arbitrary files from the target server via a path traversal issue in:
wp-content/plugins/seo-local-rank/admin/vendor/datatables/examples/resources/examples.php
The exploit attempts to retrieve:
wp-config.php
and saves the response locally.
Install dependencies:
pip install requests
python wp.py -u http://127.0.0.1
| Argument | Description |
|---|---|
-u, --url | Target URL |
This project is provided for educational purposes and authorized security testing only. The author is not responsible for misuse or damage caused by this code.