On this page

Atomicorp WAF Rule 381206

Rule Summary

  • Rule ID: 381206
  • Status: Active
  • Alert message: Atomicorp.com WAF Rules - Virtual Just In Time Patch: Access to WordPress configuration file blocked
  • Observed CWEs: CWE-22 (18), CWE-73 (1), CWE-94 (1), CWE-829 (1)
  • Revision: 4
  • Rule severity: Critical (2)
  • Request surfaces: Request filename, Request arguments, JSON request data, SOAP request data
  • Rule action: deny
  • Logging: log, auditlog

Description

This rule detects when a client attempts to directly access the “wp-config.php”. This rule does not prevent or alert if Wordpress itself reads this file.

Clients do not need to directly access this file, and it is recommended by WordPress that you block all access to this file. This file contains sensitive information about the Wordpress site, including passwords, that if disclosed will allow an attacker to gain full control of the WordPress site, including the ability to replace and install software.

False Positives

No known false positives.

Tuning Guidance

None.

This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.

CVEVulnerabilityProductCVSSSeverity
CVE-2024-6460WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusiontradedoubler-affiliate-tracker9.8 (v3.1)Critical
CVE-2025-2558WordPress The Wound Theme <= 0.0.1 - Local File Inclusionthe wound8.6 (v3.1)High
CVE-2008-1059WordPress Sniplets 1.1.2 - Local File Inclusionsniplets plugin7.5 (v2.0)High
CVE-2015-9406mTheme Unus < 2.3 - Directory Traversalmtheme-unus7.5 (v3.1)High
CVE-2016-10924Wordpress Zedna eBook download <1.2 - Local File Inclusionzedna ebook download7.5 (v3.0)High
CVE-2018-20463WordPress JSmol2WP <=1.07 - Local File Inclusionjsmol2wp7.5 (v3.0)High
CVE-2018-7422WordPress Site Editor <=1.1.1 - Local File Inclusionsite editor7.5 (v3.0)High
CVE-2018-9118WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusionwp background takeover advertisements7.5 (v3.0)High
CVE-2019-14205WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusionadaptive images7.5 (v3.1)High
CVE-2019-25213WordPress Advanced Access Manager - Path Traversaladvanced access manager7.5 (v3.1)High
CVE-2020-11738WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusionduplicator7.5 (v3.1)High
CVE-2021-39312WordPress True Ranker <2.2.4 - Local File Inclusiontrue ranker7.5 (v3.1)High
CVE-2022-1119WordPress Simple File List <3.2.8 - Local File Inclusionsimple-file-list7.5 (v3.1)High
CVE-2023-0159Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCEextensive vc addons for wpbakery page builder7.5 (v3.1)High
CVE-2026-1557WP Responsive Images <= 1.0 - Arbitrary File ReadWP Responsive Images7.5 (v3.1)High
CVE-2023-2745WordPress Core <=6.2 - Directory TraversalWordPress5.4 (v3.1)Medium
CVE-2013-7240WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversaladvanced dewplayer5.0 (v2.0)Medium
CVE-2014-5368WordPress Plugin WP Content Source Control - Directory Traversalwp content source control5.0 (v2.0)Medium
CVE-2014-8799WordPress Plugin DukaPress 2.5.2 - Directory Traversaldukapress5.0 (v2.0)Medium
CVE-2014-9119WordPress DB Backup <=4.5 - Local File Inclusiondb backup5.0 (v2.0)Medium
CVE-2015-1579WordPress Slider Revolution - Local File Disclosuredivi5.0 (v2.0)Medium
CVE-2021-24966WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated)error log viewer4.9 (v3.1)Medium
CVE-2024-10708System Dashboard < 2.8.15 - Admin+ Path Traversalsystem dashboard4.9 (v3.1)Medium

Observed CWEs

These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.

CWERelated Published CVEs
CWE-22CVE-2015-9406 , CVE-2016-10924 , CVE-2018-20463 , CVE-2018-7422 , CVE-2018-9118 , CVE-2019-14205 , CVE-2019-25213 , CVE-2020-11738 , CVE-2021-39312 , CVE-2022-1119 , CVE-2026-1557 , CVE-2023-2745 , CVE-2013-7240 , CVE-2014-5368 , CVE-2014-8799 , CVE-2014-9119 , CVE-2015-1579 , CVE-2024-10708
CWE-73CVE-2021-24966
CWE-94CVE-2008-1059
CWE-829CVE-2018-7422

Documentation Source

  • Original wiki page: WAF 381206
  • Source revision: 2351
  • Source revision date: 2012-06-07