
Detailed penetration test report demonstrating unauthenticated path traversal (CVE-2019-11447) in WordPress Simple Backup plugin, including exploitation steps, impact analysis, and remediation guidance.
| Item | Details |
|---|---|
| Document Title | Penetration Test Report - WordPress Path Traversal |
| Client/Exam | HackTheBox Lab - CPTS Exercise 1 |
| Date | August 22, 2026 |
| Assessor | Fernando Viana (Penetration Tester) |
| Assessment Type | Gray Box (External, No Credentials) |
| Lab Environment | 154.57.164.73:30706 |
| Lab Duration | 1 Hour |
| Objectives | Identify and exploit vulnerabilities to retrieve restricted files |
| Flag Obtained | HTB{my_f1r57_h4ck} |
During this penetration assessment of the web application hosted on 154.57.164.73:30706, a critical vulnerability was identified that allows unauthenticated attackers to download and read arbitrary files from the server filesystem.
The vulnerable WordPress installation contains an outdated plugin (Simple Backup v2.7.10) with a path traversal vulnerability (CVE-2019-11447) that permits unauthorized file access without requiring authentication or authorization.
This vulnerability was successfully exploited to retrieve the /flag.txt file from the server root, confirming complete compromise of confidentiality. An attacker with this access could:
wp-config.php, .env)Critical action is required to remediate this vulnerability immediately, as it poses an extreme risk to data security, privacy compliance (GDPR, HIPAA, PCI-DSS), and system integrity.
| Severity | Count | Business Impact |
|---|---|---|
| 🔴 CRITICAL | 1 | Complete confidentiality breach; unauthorized file access |
| 🟠 HIGH | 0 | — |
| 🟡 MEDIUM | 0 | — |
| 🟢 LOW | 0 | — |
| ℹ️ INFORMATIONAL | 1 | Outdated software versions detected |
Assessment Type: Gray Box (external attacker, no credentials provided, network access available)
Assessment Dates: August 22, 2026
Testing Approach: Non-evasive, methodical assessment following industry-standard penetration testing framework (PTES):
CVE-2019-11447 | CWE-22: Improper Limitation of a Pathname to a Restricted Directory
The WordPress plugin Simple Backup (version 2.7.10/2.7.11, Exploit-DB 39883) contains a path traversal vulnerability in its admin "Backup Manager" page. The plugin fails to sanitize the file path supplied through the download_backup_file GET parameter, allowing an attacker to traverse outside the intended simple-backup/ directory using relative path sequences (../) and download any file readable by the web server process — including files at the filesystem root.
The vulnerable endpoint:
GET /wp-admin/tools.php?page=backup_manager&download_backup_file=../../../../../../../../../../flag.txt
page=backup_manager routes the request into the plugin's admin page handler; download_backup_file is the parameter the plugin's code reads directly and concatenates into a filesystem path without validation, allowing directory traversal.
7.5 - HIGH (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N)
Confidentiality Breach: ⚠️ CRITICAL
Attackers can read any file accessible to the web server, including:
| File | Impact | Risk Level |
|---|---|---|
/wp-config.php | Database credentials, salts, keys | 🔴 CRITICAL |
/.env | API keys, secrets, configuration | 🔴 CRITICAL |
/etc/passwd | User enumeration, system mapping | 🟠 HIGH |
SSH keys (.ssh/id_rsa) | Lateral movement, system access | 🔴 CRITICAL |
/proc/self/environ | Running application secrets | 🟠 HIGH |
| User uploads directory | Private files, media | 🟠 HIGH |
Regulatory Impact:
The Exploit-DB advisory (39883.txt, read via searchsploit -x — see ht4-poc.png) documents the plugin's delete primitive from simple-backup-manager.php:
if(array_key_exists('delete_backup_file', $_GET)){
$this->delete_local_backup_file($_GET['delete_backup_file']);
}
$bk_dir = ABSPATH."simple-backup/";
unlink($bk_dir . $filename);
$filename comes straight from $_GET['delete_backup_file'] with no basename() or path-containment check. Passing ../pizza.txt resolves $bk_dir . $filename to .../simple-backup/../pizza.txt → .../pizza.txt, escaping the intended backup folder.
The download primitive actually exploited in this engagement (download_backup_file) follows the exact same unsanitized concatenation pattern in the same plugin, but serves the file back to the requester instead of deleting it — which is what allowed retrieval of /flag.txt from the filesystem root (10× ../ from ABSPATH/simple-backup/).
The Problem:
basename() to remove directory componentsrealpath() stays within ABSPATH."simple-backup/"current_user_can() / authentication check before serving the file — the handler runs on plugin load, before WordPress's own wp-admin auth gate, so it is reachable without being logged inConnected directly to the target via browser (http://154.57.164.73:30706/). The WordPress installation is titled "GETTING STARTED", and a public blog post on the homepage discloses the exact plugin name and version in plain text: "Simple Backup Plugin 2.7.10 for WordPress" — no enumeration tooling was even required to fingerprint the vulnerable component.

whatweb http://154.57.164.73:30706/
Result: Apache/2.4.41 (Ubuntu Linux), WordPress 5.6.1 confirmed via MetaGenerator and WordPress plugin signatures.

searchsploit simple backup wordpress