Files
nuclei-templates/http/vulnerabilities/wordpress/wordpress-updraftplus-pem-key.yaml
2025-10-26 16:17:37 +00:00

32 lines
849 B
YAML

id: updraftplus-pem-keys
info:
name: UpdraftPlus Plugin Pem Key
author: dhiyaneshDk
severity: info
description: UpdraftPlus wordpress plugin private key leaked with directory listing.
reference:
- https://www.exploit-db.com/ghdb/6437
metadata:
max-request: 1
tags: wp-plugin,edb,wordpress,vuln
http:
- method: GET
path:
- '{{BaseURL}}/wp-content/plugins/updraftplus/includes/'
matchers-condition: and
matchers:
- type: word
words:
- "Index of /"
- ".pem"
- "updraftplus"
condition: and
part: body
- type: status
status:
- 200
# digest: 4a0a00473045022100e0124a4428a3d6badb43de40ee528ca54830e064a0176a0063fcaa48fd8370f50220189e708b55b5175b6e87032ef45551fed1216fa98668a0edce7d7a30e5401e0b:922c64590222798bb761d5b6d8e72950