==================================================================================================================================== | # Title : WordPress BackUpWordPress 3.8 Plugins Backup Disclosure Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0(64-bit) | | # Vendor : https://wordpress.org/plugins/backupwordpress/ | | # Dork : "/wp-content/backupwordpress- " | ==================================================================================================================================== poc : [+] Dorking İn Google Or Other Search Enggine. [+] appears to leave backups in a world accessible directory under the document root. [+] Use Dork : "/wp-content/backupwordpress- " [+] The search result gives you some websites that took earlier a Wordpress backup. [+] http://127.0.0.1/WordPress3/wp-content/backupwordpress-89c0bd0079-backups/ ====Greetings to :========================================================================================================================= | jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * djroot.dz * LiquidWorm* Hussin-X *D4NB4R * shadow_00715 * yasMouh | ===========================================================================================================================================