On this page
Atomicorp WAF Rule 347006
Rule Summary
- Rule ID: 347006
- Status: Active
- Alert message: Atomicorp.com WAF Rules: Generic Path Recursion denied in URI/ARGS
- Observed CWEs: CWE-22 (7), CWE-98 (3), CWE-327 (1), CWE-352 (1), CWE-552 (1)
- Revision: 69
- Rule severity: Critical (2)
- Phase: 2 (request body)
- Request surfaces: Request filename, Request headers, Request arguments, JSON request data, SOAP request data
- Rule action: deny
- HTTP status: 403
- Logging: log, auditlog
Description
This rule detects behavior identified by its current alert as “Generic Path Recursion denied in URI/ARGS” in the request filename, request headers, request arguments, JSON request data, SOAP request data. It evaluates during the request body phase and denies matching traffic with HTTP status 403.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2023-5815 | News & Blog Designer Pack – WordPress Blog Plugin <= 3.4.1 - Unauthenticated Local File Inclusion | news & blog designer pack | 9.8 (v3.1) | Critical |
| CVE-2024-10571 | Chartify – WordPress Chart Plugin < 2.9.6 - Local File Inclusion | chartify | 9.8 (v3.1) | Critical |
| CVE-2024-6460 | WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusion | tradedoubler-affiliate-tracker | 9.8 (v3.1) | Critical |
| CVE-2024-9193 | WHMpress <= 6.3-revision-0 - Unauthenticated Local File Inclusion to Arbitrary Options Update | whmcs | 9.8 (v3.1) | Critical |
| CVE-2026-11974 | Media folder Addon < 4.1.7 - Unauthenticated Arbitrary File Download | wp-media-folder-addon | 8.6 (v3.1) | High |
| CVE-2020-36836 | WordPress WP Fastest Cache <= 0.9.0.2 - Authenticated Arbitrary File Deletion | wp fastest cache | 8.0 (v3.1) | High |
| CVE-2020-11738 | WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion | duplicator | 7.5 (v3.1) | High |
| CVE-2022-33901 | WordPress MultiSafepay for WooCommerce <=4.13.1 - Arbitrary File Read | multisafepay plugin for woocommerce | 7.5 (v3.1) | High |
| CVE-2025-2539 | File Away <= 3.9.9.0.1 - Missing Authorization to Unauthenticated Arbitrary File Read | file away | 7.5 (v3.1) | High |
| CVE-2026-15244 | HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search | HUSKY | 7.2 (v3.1) | High |
| CVE-2026-12898 | All-in-One WP Migration and Backup < 7.106 - Arbitrary Log File Write | all-in-one-wp-migration | 6.5 (v3.1) | Medium |
| CVE-2022-4320 | WordPress Events Calendar <1.4.5 - Cross-Site Scripting | wordpress events calendar plugin | 6.1 (v3.1) | Medium |
| CVE-2026-13693 | Bit Form < 3.1.0 - Unauthenticated Arbitrary File Read via Path Traversal | Bit Form | 5.9 (v3.1) | Medium |
| CVE-2026-9062 | Agile Store Locator < 1.6.9 - Admin+ Arbitrary File Read via Path Traversal | Store Locator WordPress | 3.4 (v3.1) | Low |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.