Skip to content

Commit d47bf22

Browse files
authored
Merge pull request #14231 from projectdiscovery/Akokonunes-patch-9
Create wp-mailchimp-for-wp-fpd.yaml
2 parents 9d1450d + 77fd542 commit d47bf22

File tree

1 file changed

+26
-0
lines changed

1 file changed

+26
-0
lines changed
Lines changed: 26 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,26 @@
1+
id: wp-mailchimp-for-wp-fpd
2+
3+
info:
4+
name: WordPress Mailchimp for WordPress Plugin - Full Path Disclosure
5+
author: 0x_Akoko
6+
severity: info
7+
description: |
8+
WordPress plugin MC4WP: Mailchimp for WordPress internal file system path is exposed.
9+
reference:
10+
- https://wordpress.org/plugins/mailchimp-for-wp/
11+
metadata:
12+
verified: true
13+
max-request: 1
14+
tags: debug,wordpress,fpd,vuln,mailchimp,wp-plugin
15+
16+
http:
17+
- method: GET
18+
path:
19+
- "{{BaseURL}}/wp-content/plugins/mailchimp-for-wp/integrations/bootstrap.php"
20+
21+
matchers:
22+
- type: dsl
23+
dsl:
24+
- 'status_code == 200'
25+
- 'contains_all(body, "Fatal error", "Call to undefined function", "mailchimp-for-wp/integrations/bootstrap.php")'
26+
condition: and

0 commit comments

Comments
 (0)