216.73.217.22

CVE-2021-47977

· Published 16/05/2026 16:16 · Modified 16/05/2026 16:16

Labels: CVE-2021-47977 2026-05-16CVE-2021-47977CWE-22[email protected]

Essential information

Published
16/05/2026 16:16
Modified
16/05/2026 16:16
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter. Attackers can send requests to the duplicator_download action via admin-ajax.php with path traversal sequences to access sensitive system files outside the intended directory.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
wordpress / anti-malware security and bruteforce firewall cpe:2.3:a:wordpress:anti-malware_security_and_bruteforce_firewall:4.20.59:*:*:*:*:*:*:*

References