On this page

Atomicorp WAF Rule 336461

Rule Summary

  • Rule ID: 336461
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules - Virtual Just In Time Patch: Possible attempt to maliciously access wp-config.php file
  • Observed CWEs: CWE-22 (19), CWE-73 (1), CWE-94 (1), CWE-829 (1)
  • Revision: 8
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request arguments, JSON request data, SOAP request data
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule detects when a client attempts to access the wp-config.php file. This file contains the credentials to control a Wordpress site. Gaining access to this file will allow a user to fully control a WordPress site. This is likely an attack on the system.

Troubleshooting

False Positives

There are no known false positives with this rule. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Do not disable this rule.

Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2024-6460WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusiontradedoubler-affiliate-tracker9.8 (v3.1)Critical
CVE-2025-2558WordPress The Wound Theme <= 0.0.1 - Local File Inclusionthe wound8.6 (v3.1)High
CVE-2008-1059WordPress Sniplets 1.1.2 - Local File Inclusionsniplets plugin7.5 (v2.0)High
CVE-2015-9406mTheme Unus < 2.3 - Directory Traversalmtheme-unus7.5 (v3.1)High
CVE-2016-10924Wordpress Zedna eBook download <1.2 - Local File Inclusionzedna ebook download7.5 (v3.0)High
CVE-2018-7422WordPress Site Editor <=1.1.1 - Local File Inclusionsite editor7.5 (v3.0)High
CVE-2018-9118WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusionwp background takeover advertisements7.5 (v3.0)High
CVE-2019-14205WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusionadaptive images7.5 (v3.1)High
CVE-2019-25213WordPress Advanced Access Manager - Path Traversaladvanced access manager7.5 (v3.1)High
CVE-2020-11738WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusionduplicator7.5 (v3.1)High
CVE-2021-39312WordPress True Ranker <2.2.4 - Local File Inclusiontrue ranker7.5 (v3.1)High
CVE-2022-1119WordPress Simple File List <3.2.8 - Local File Inclusionsimple-file-list7.5 (v3.1)High
CVE-2025-10162WordPress OrderConvo < 14 - Path TraversalAdmin and Customer Messages After Order for WooCommerce: OrderConvo7.5 (v3.1)High
CVE-2025-13339Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File ReadHippoo Mobile App for WooCommerce7.5 (v3.1)High
CVE-2026-1557WP Responsive Images <= 1.0 - Arbitrary File ReadWP Responsive Images7.5 (v3.1)High
CVE-2026-9282W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File ReadW3 Total Cache7.5 (v3.1)High
CVE-2023-2745WordPress Core <=6.2 - Directory TraversalWordPress5.4 (v3.1)Medium
CVE-2013-7240WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversaladvanced dewplayer5.0 (v2.0)Medium
CVE-2014-5368WordPress Plugin WP Content Source Control - Directory Traversalwp content source control5.0 (v2.0)Medium
CVE-2014-8799WordPress Plugin DukaPress 2.5.2 - Directory Traversaldukapress5.0 (v2.0)Medium
CVE-2014-9119WordPress DB Backup <=4.5 - Local File Inclusiondb backup5.0 (v2.0)Medium
CVE-2015-1579WordPress Slider Revolution - Local File Disclosuredivi5.0 (v2.0)Medium
CVE-2021-24966WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)error log viewer4.9 (v3.1)Medium
CVE-2024-10708System Dashboard < 2.8.15 - Admin+ Path Traversalsystem dashboard4.9 (v3.1)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-22CVE-2015-9406 , CVE-2016-10924 , CVE-2018-7422 , CVE-2018-9118 , CVE-2019-14205 , CVE-2019-25213 , CVE-2020-11738 , CVE-2021-39312 , CVE-2022-1119 , CVE-2025-13339 , CVE-2026-1557 , CVE-2026-9282 , CVE-2023-2745 , CVE-2013-7240 , CVE-2014-5368 , CVE-2014-8799 , CVE-2014-9119 , CVE-2015-1579 , CVE-2024-10708
CWE-73CVE-2021-24966
CWE-94CVE-2008-1059
CWE-829CVE-2018-7422

Documentation Source

  • Original wiki page: WAF 336461
  • Source revision: 6065
  • Source revision date: 2020-08-24