On this page
Atomicorp WAF Rule 381206
Rule Summary
- Rule ID: 381206
- Status: Active
- Alert message: Atomicorp.com WAF Rules - Virtual Just In Time Patch: Access to WordPress configuration file blocked
- Observed CWEs: CWE-22 (18), CWE-73 (1), CWE-94 (1), CWE-829 (1)
- Revision: 4
- Rule severity: Critical (2)
- Request surfaces: Request filename, Request arguments, JSON request data, SOAP request data
- Rule action: deny
- Logging: log, auditlog
Description
This rule detects when a client attempts to directly access the “wp-config.php”. This rule does not prevent or alert if Wordpress itself reads this file.
Clients do not need to directly access this file, and it is recommended by WordPress that you block all access to this file. This file contains sensitive information about the Wordpress site, including passwords, that if disclosed will allow an attacker to gain full control of the WordPress site, including the ability to replace and install software.
False Positives
No known false positives.
Tuning Guidance
None.
Selected Related CVEs
This is a selected list of documented research observations, not an exhaustive coverage matrix. Absence of a CVE does not imply absence of protection.
| CVE | Vulnerability | Product | CVSS | Severity |
|---|---|---|---|---|
| CVE-2024-6460 | WordPress Grow by Tradedoubler Plugin < 2.0.22 - Unauthenticated Local File Inclusion | tradedoubler-affiliate-tracker | 9.8 (v3.1) | Critical |
| CVE-2025-2558 | WordPress The Wound Theme <= 0.0.1 - Local File Inclusion | the wound | 8.6 (v3.1) | High |
| CVE-2008-1059 | WordPress Sniplets 1.1.2 - Local File Inclusion | sniplets plugin | 7.5 (v2.0) | High |
| CVE-2015-9406 | mTheme Unus < 2.3 - Directory Traversal | mtheme-unus | 7.5 (v3.1) | High |
| CVE-2016-10924 | Wordpress Zedna eBook download <1.2 - Local File Inclusion | zedna ebook download | 7.5 (v3.0) | High |
| CVE-2018-20463 | WordPress JSmol2WP <=1.07 - Local File Inclusion | jsmol2wp | 7.5 (v3.0) | High |
| CVE-2018-7422 | WordPress Site Editor <=1.1.1 - Local File Inclusion | site editor | 7.5 (v3.0) | High |
| CVE-2018-9118 | WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion | wp background takeover advertisements | 7.5 (v3.0) | High |
| CVE-2019-14205 | WordPress Nevma Adaptive Images <0.6.67 - Local File Inclusion | adaptive images | 7.5 (v3.1) | High |
| CVE-2019-25213 | WordPress Advanced Access Manager - Path Traversal | advanced access manager | 7.5 (v3.1) | High |
| CVE-2020-11738 | WordPress Duplicator 1.3.24 & 1.3.26 - Local File Inclusion | duplicator | 7.5 (v3.1) | High |
| CVE-2021-39312 | WordPress True Ranker <2.2.4 - Local File Inclusion | true ranker | 7.5 (v3.1) | High |
| CVE-2022-1119 | WordPress Simple File List <3.2.8 - Local File Inclusion | simple-file-list | 7.5 (v3.1) | High |
| CVE-2023-0159 | Extensive VC Addons for WPBakery page builder < 1.9.1 - Unauthenticated RCE | extensive vc addons for wpbakery page builder | 7.5 (v3.1) | High |
| CVE-2026-1557 | WP Responsive Images <= 1.0 - Arbitrary File Read | WP Responsive Images | 7.5 (v3.1) | High |
| CVE-2023-2745 | WordPress Core <=6.2 - Directory Traversal | WordPress | 5.4 (v3.1) | Medium |
| CVE-2013-7240 | WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversal | advanced dewplayer | 5.0 (v2.0) | Medium |
| CVE-2014-5368 | WordPress Plugin WP Content Source Control - Directory Traversal | wp content source control | 5.0 (v2.0) | Medium |
| CVE-2014-8799 | WordPress Plugin DukaPress 2.5.2 - Directory Traversal | dukapress | 5.0 (v2.0) | Medium |
| CVE-2014-9119 | WordPress DB Backup <=4.5 - Local File Inclusion | db backup | 5.0 (v2.0) | Medium |
| CVE-2015-1579 | WordPress Slider Revolution - Local File Disclosure | divi | 5.0 (v2.0) | Medium |
| CVE-2021-24966 | WordPress Plugin Error Log Viewer 1.1.1 - Arbitrary File Clearing (Authenticated) | error log viewer | 4.9 (v3.1) | Medium |
| CVE-2024-10708 | System Dashboard < 2.8.15 - Admin+ Path Traversal | system dashboard | 4.9 (v3.1) | Medium |
Observed CWEs
These CWEs are recorded on published CVEs in the selected observations associated with this rule. They are observational relationships, not a claim that the rule universally blocks every vulnerability assigned to a CWE.
Documentation Source
- Original wiki page: WAF 381206
- Source revision: 2351
- Source revision date: 2012-06-07