On this page
Atomicorp WAF Rule 336461
Rule Summary
- Rule ID: 336461
- Status: Active
- Alert message: Atomicorp.com WAF Rules - Virtual Just In Time Patch: Possible attempt to maliciously access wp-config.php file
- Observed CWEs: CWE-22 (19), CWE-73 (1), CWE-94 (1), CWE-829 (1)
- Revision: 8
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects when a client attempts to access the wp-config.php file. This file contains the credentials to control a Wordpress site. Gaining access to this file will allow a user to fully control a WordPress site. This is likely an attack on the system.
Troubleshooting
False Positives
There are no known false positives with this rule. If you believe this is a false positive, please report this to our security team to determine if this is a legitimate case, or if its clever attack on your system. Do not disable this rule.
Instructions to report false positives are detailed on the Reporting False Positives wiki page. If it is a false positive, we will fix the issue in the rules and get a release out to you promptly.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2024-6460 | WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusion | tradedoubler-affiliate-tracker | 9.8 (v3.1) | Critical |
| CVE-2025-2558 | WordPress The Wound Theme <= 0.0.1 - Local File Inclusion | the wound | 8.6 (v3.1) | High |
| CVE-2008-1059 | WordPress Sniplets 1.1.2 - Local File Inclusion | sniplets plugin | 7.5 (v2.0) | High |
| CVE-2015-9406 | mTheme Unus < 2.3 - Directory Traversal | mtheme-unus | 7.5 (v3.1) | High |
| CVE-2016-10924 | Wordpress Zedna eBook download <1.2 - Local File Inclusion | zedna ebook download | 7.5 (v3.0) | High |
| CVE-2018-7422 | WordPress Site Editor <=1.1.1 - Local File Inclusion | site editor | 7.5 (v3.0) | High |
| CVE-2018-9118 | WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion | wp background takeover advertisements | 7.5 (v3.0) | High |
| CVE-2019-14205 | WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion | adaptive images | 7.5 (v3.1) | High |
| CVE-2019-25213 | WordPress Advanced Access Manager - Path Traversal | advanced access manager | 7.5 (v3.1) | High |
| CVE-2020-11738 | WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion | duplicator | 7.5 (v3.1) | High |
| CVE-2021-39312 | WordPress True Ranker <2.2.4 - Local File Inclusion | true ranker | 7.5 (v3.1) | High |
| CVE-2022-1119 | WordPress Simple File List <3.2.8 - Local File Inclusion | simple-file-list | 7.5 (v3.1) | High |
| CVE-2025-10162 | WordPress OrderConvo < 14 - Path Traversal | Admin and Customer Messages After Order for WooCommerce: OrderConvo | 7.5 (v3.1) | High |
| CVE-2025-13339 | Hippoo Mobile App for WooCommerce <= 1.7.1 - Unauthenticated Arbitrary File Read | Hippoo Mobile App for WooCommerce | 7.5 (v3.1) | High |
| CVE-2026-1557 | WP Responsive Images <= 1.0 - Arbitrary File Read | WP Responsive Images | 7.5 (v3.1) | High |
| CVE-2026-9282 | W3 Total Cache <= 2.9.4 - Unauthenticated Arbitrary File Read | W3 Total Cache | 7.5 (v3.1) | High |
| CVE-2023-2745 | WordPress Core <=6.2 - Directory Traversal | WordPress | 5.4 (v3.1) | Medium |
| CVE-2013-7240 | WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversal | advanced dewplayer | 5.0 (v2.0) | Medium |
| CVE-2014-5368 | WordPress Plugin WP Content Source Control - Directory Traversal | wp content source control | 5.0 (v2.0) | Medium |
| CVE-2014-8799 | WordPress Plugin DukaPress 2.5.2 - Directory Traversal | dukapress | 5.0 (v2.0) | Medium |
| CVE-2014-9119 | WordPress DB Backup <=4.5 - Local File Inclusion | db backup | 5.0 (v2.0) | Medium |
| CVE-2015-1579 | WordPress Slider Revolution - Local File Disclosure | divi | 5.0 (v2.0) | Medium |
| CVE-2021-24966 | WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated) | error log viewer | 4.9 (v3.1) | Medium |
| CVE-2024-10708 | System Dashboard < 2.8.15 - Admin+ Path Traversal | system dashboard | 4.9 (v3.1) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 336461
- Source revision: 6065
- Source revision date: 2020-08-24