On this page

Atomicorp WAF Rule 347006

Rule Summary

  • Rule ID: 347006
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules: Generic Path Recursion denied in URI/ARGS
  • Observed CWEs: CWE-22 (7), CWE-98 (3), CWE-327 (1), CWE-352 (1), CWE-552 (1)
  • Revision: 69
  • Rule severity: Critical (2)
  • Phase: 2 (request body)
  • Request surfaces: Request filename, Request headers, Request arguments, JSON request data, SOAP request data
  • Rule action: deny
  • HTTP status: 403
  • Logging: log, auditlog

Description

This rule detects behavior identified by its current alert as “Generic Path Recursion denied in URI/ARGS” in the request filename, request headers, request arguments, JSON request data, SOAP request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2023-5815News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusionnews &amp; blog designer pack9.8 (v3.1)Critical
CVE-2024-10571Chartify – WordPress Chart Plugin < 2.9.6 - Local File Inclusionchartify9.8 (v3.1)Critical
CVE-2024-6460WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusiontradedoubler-affiliate-tracker9.8 (v3.1)Critical
CVE-2024-9193WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Updatewhmcs9.8 (v3.1)Critical
CVE-2026-11974Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Downloadwp-media-folder-addon8.6 (v3.1)High
CVE-2020-36836WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletionwp fastest cache8.0 (v3.1)High
CVE-2020-11738WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusionduplicator7.5 (v3.1)High
CVE-2022-33901WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Readmultisafepay plugin for woocommerce7.5 (v3.1)High
CVE-2025-2539File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Readfile away7.5 (v3.1)High
CVE-2026-15244HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter searchHUSKY7.2 (v3.1)High
CVE-2026-12898All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Writeall-in-one-wp-migration6.5 (v3.1)Medium
CVE-2022-4320WordPress Events Calendar <1.4.5 - Cross-Site Scriptingwordpress events calendar plugin6.1 (v3.1)Medium
CVE-2026-13693Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path TraversalBit Form5.9 (v3.1)Medium
CVE-2026-9062Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path TraversalStore Locator WordPress3.4 (v3.1)Low

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-22CVE-2026-11974 , CVE-2020-36836 , CVE-2020-11738 , CVE-2026-15244 , CVE-2026-12898 , CVE-2026-13693 , CVE-2026-9062
CWE-98CVE-2023-5815 , CVE-2024-10571 , CVE-2024-9193
CWE-327CVE-2025-2539
CWE-352CVE-2020-36836
CWE-552CVE-2022-33901