Skip to content
KitploitKITPLOIT
ИнструментыБлог
Log in
Отправить
ИнструментыБлог
Отправить

Инструменты для хакинга, пентеста и кибербезопасности — ваш арсенал защиты!

Kitploit — это каталог инструментов для хакинга, кибербезопасности и пентестинга. Находите последние обновления проектов для поиска уязвимостей, анализа систем, автоматизации тестирования и усиления вашей безопасности.

ЛентыКонтактыКонфиденциальность© 2026 Kitploit

Каталог инструментов

Категории

Все категории
Loading categories
WordPress-Path-Traversal-CVE-2019-11447 — Detailed penetration test report demonstrating unauthenticated path traversal (CVE-2019-11447) in WordPress Simple Backup plugin, including exploitation steps, impact analysis, and remediation guidance. | Kitploit
Инструменты/GitHubGitHub/capivara-research/wordpress-path-traversal-cve-2019-11447
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubcapivara-research/wordpress-path-traversal-cve-2019-11447

WordPress-Path-Traversal-CVE-2019-11447

Detailed penetration test report demonstrating unauthenticated path traversal (CVE-2019-11447) in WordPress Simple Backup plugin, including exploitation steps, impact analysis, and remediation guidance.

Репозиторий
1717 дней назадЕщё не проверено

Популярное

Смотреть все →

Откройте для себя самые используемые инструменты нашего сообщества.

Изучить все инструменты

Просмотрите нашу коллекцию инструментов

Смотреть все инструменты →
Поделиться
Контент недоступен на запрошенном языке. Показываем английскую версию.

Penetration Test Report

WordPress Path Traversal - CVE-2019-11447


Document Information

ItemDetails
Document TitlePenetration Test Report - WordPress Path Traversal
Client/ExamHackTheBox Lab - CPTS Exercise 1
DateAugust 22, 2026
AssessorFernando Viana (Penetration Tester)
Assessment TypeGray Box (External, No Credentials)
Lab Environment154.57.164.73:30706
Lab Duration1 Hour
ObjectivesIdentify and exploit vulnerabilities to retrieve restricted files
Flag ObtainedHTB{my_f1r57_h4ck}

Executive Summary

During this penetration assessment of the web application hosted on 154.57.164.73:30706, a critical vulnerability was identified that allows unauthenticated attackers to download and read arbitrary files from the server filesystem.

The vulnerable WordPress installation contains an outdated plugin (Simple Backup v2.7.10) with a path traversal vulnerability (CVE-2019-11447) that permits unauthorized file access without requiring authentication or authorization.

This vulnerability was successfully exploited to retrieve the /flag.txt file from the server root, confirming complete compromise of confidentiality. An attacker with this access could:

  • Extract sensitive configuration files (wp-config.php, .env)
  • Read database credentials and user data
  • Access private SSH keys and authentication tokens
  • Potentially escalate privileges through leaked credentials
  • Harvest personal information for further attacks

Critical action is required to remediate this vulnerability immediately, as it poses an extreme risk to data security, privacy compliance (GDPR, HIPAA, PCI-DSS), and system integrity.


Assessment Overview

SeverityCountBusiness Impact
🔴 CRITICAL1Complete confidentiality breach; unauthorized file access
🟠 HIGH0—
🟡 MEDIUM0—
🟢 LOW0—
ℹ️ INFORMATIONAL1Outdated software versions detected

Methodology

Assessment Type: Gray Box (external attacker, no credentials provided, network access available)

Assessment Dates: August 22, 2026

Testing Approach: Non-evasive, methodical assessment following industry-standard penetration testing framework (PTES):

  1. Reconnaissance — Passive information gathering
  2. Scanning & Enumeration — Active service discovery
  3. Vulnerability Analysis — Identification of weaknesses
  4. Exploitation — Proof of concept development
  5. Post-Exploitation — Impact demonstration
  6. Reporting — Documentation and remediation guidance

Findings

🔴 CRITICAL - Path Traversal & Arbitrary File Download

CVE-2019-11447 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory


Description

The WordPress plugin Simple Backup (version 2.7.10/2.7.11, Exploit-DB 39883) contains a path traversal vulnerability in its admin "Backup Manager" page. The plugin fails to sanitize the file path supplied through the download_backup_file GET parameter, allowing an attacker to traverse outside the intended simple-backup/ directory using relative path sequences (../) and download any file readable by the web server process — including files at the filesystem root.

The vulnerable endpoint:

GET /wp-admin/tools.php?page=backup_manager&download_backup_file=../../../../../../../../../../flag.txt

page=backup_manager routes the request into the plugin's admin page handler; download_backup_file is the parameter the plugin's code reads directly and concatenates into a filesystem path without validation, allowing directory traversal.


CVSS v3.1 Score

7.5 - HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)

  • Attack Vector (AV): Network
  • Attack Complexity (AC): Low
  • Privileges Required (PR): None
  • User Interaction (UI): None
  • Scope (S): Unchanged
  • Confidentiality (C): High
  • Integrity (I): None
  • Availability (A): None

Business Impact

Confidentiality Breach: ⚠️ CRITICAL

Attackers can read any file accessible to the web server, including:

FileImpactRisk Level
/wp-config.phpDatabase credentials, salts, keys🔴 CRITICAL
/.envAPI keys, secrets, configuration🔴 CRITICAL
/etc/passwdUser enumeration, system mapping🟠 HIGH
SSH keys (.ssh/id_rsa)Lateral movement, system access🔴 CRITICAL
/proc/self/environRunning application secrets🟠 HIGH
User uploads directoryPrivate files, media🟠 HIGH

Regulatory Impact:

  • GDPR Violation: Unauthorized access to user data
  • HIPAA Violation: Protected health information exposure
  • PCI-DSS Violation: Credit card data or payment info access
  • SOC 2 Violation: Confidentiality requirement breach

Vulnerable Code Pattern

The Exploit-DB advisory (39883.txt, read via searchsploit -x — see ht4-poc.png) documents the plugin's delete primitive from simple-backup-manager.php:

if(array_key_exists('delete_backup_file', $_GET)){
    $this->delete_local_backup_file($_GET['delete_backup_file']);
}
$bk_dir = ABSPATH."simple-backup/";
unlink($bk_dir . $filename);

$filename comes straight from $_GET['delete_backup_file'] with no basename() or path-containment check. Passing ../pizza.txt resolves $bk_dir . $filename to .../simple-backup/../pizza.txt → .../pizza.txt, escaping the intended backup folder.

The download primitive actually exploited in this engagement (download_backup_file) follows the exact same unsanitized concatenation pattern in the same plugin, but serves the file back to the requester instead of deleting it — which is what allowed retrieval of /flag.txt from the filesystem root (10× ../ from ABSPATH/simple-backup/).

The Problem:

  • No use of basename() to remove directory components
  • No whitelist of allowed files
  • No validation that realpath() stays within ABSPATH."simple-backup/"
  • Direct concatenation of user input into the file path
  • No current_user_can() / authentication check before serving the file — the handler runs on plugin load, before WordPress's own wp-admin auth gate, so it is reachable without being logged in

Proof of Concept

Phase 1: Initial Access — Application Identification

Connected directly to the target via browser (http://154.57.164.73:30706/). The WordPress installation is titled "GETTING STARTED", and a public blog post on the homepage discloses the exact plugin name and version in plain text: "Simple Backup Plugin 2.7.10 for WordPress" — no enumeration tooling was even required to fingerprint the vulnerable component.

Initial Access - Plugin version disclosed on WordPress homepage

Phase 2: Service Fingerprinting

whatweb http://154.57.164.73:30706/

Result: Apache/2.4.41 (Ubuntu Linux), WordPress 5.6.1 confirmed via MetaGenerator and WordPress plugin signatures.

Service Fingerprinting - whatweb output

Phase 3: Vulnerability Research

searchsploit simple backup wordpress
Скачать инструмент