Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
wordpress-true-ranker-cve-2021-39312 — Exploit-WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read | Kitploit
Tools/GitHubGitHub/root-wav/wordpress-true-ranker-cve-2021-39312
Vulnerability AnalysisExploitationWeb Application ExploitationInformation GatheringPenetration TestingLearning & Education
GitHubroot-wav/wordpress-true-ranker-cve-2021-39312

wordpress-true-ranker-cve-2021-39312

Exploit-WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read

View Repository
63 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

WordPress Plugin The True Ranker 2.2.2 - Arbitrary File Read

Python proof-of-concept for CVE-2021-39312, affecting The True Ranker (seo-local-rank) WordPress plugin versions ≤ 2.2.2.

Vulnerability Details

  • CVE: CVE-2021-39312
  • Type: Arbitrary File Read
  • Affected Plugin: The True Ranker
  • Affected Versions: ≤ 2.2.2
  • Vendor Homepage: https://wordpress.org/plugins/seo-local-rank/
  • Plugin Source: https://plugins.svn.wordpress.org/seo-local-rank/tags/2.2.2/

Description

The vulnerability allows an attacker to read arbitrary files from the target server via a path traversal issue in:

wp-content/plugins/seo-local-rank/admin/vendor/datatables/examples/resources/examples.php

The exploit attempts to retrieve:

wp-config.php

and saves the response locally.

Requirements

Install dependencies:

pip install requests

Usage

python wp.py -u http://127.0.0.1

Arguments

ArgumentDescription
-u, --urlTarget URL

Tested On

  • Linux

References

  • CVE-2021-39312
  • https://wordpress.org/plugins/seo-local-rank/
  • https://plugins.svn.wordpress.org/seo-local-rank/tags/2.2.2/

Disclaimer

This project is provided for educational purposes and authorized security testing only. The author is not responsible for misuse or damage caused by this code.

Download Tool