S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-39327 Scanner

CVE-2021-39327 scanner - Information Disclosure vulnerability in BulletProof Security plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2k
Times Used
continuous scan runs
5.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-39327
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

The BulletProof Security WordPress plugin is vulnerable to sensitive information disclosure due to a file path disclosure in the publicly accessible ~/db_backup_log.txt file which grants attackers the full path of the site, in addition to the path of database backup files. This affects versions up to, and including, 5.1.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
BulletProof Securityby AITpro
5.1
Updated Aug 21, 2026View on NVD →
Detail

The BulletProof Security plugin for WordPress is a security tool that offers website owners an extra layer of protection against potential cyber attacks. This plugin offers many features, such as malware scanning, login security, and firewall protection, all of which aim to keep the site and its content safe and secure from malicious actors. The plugin is widely used by site owners who value the security of their digital assets.

One vulnerability that has been detected in the BulletProof Security plugin is CVE-2021-39327. This vulnerability is caused by a file path disclosure in the publicly accessible ~/db_backup_log.txt file. This disclosure grants attackers access to the full path of the site, in addition to the path of database backup files. This means that an attacker can easily locate and gain unauthorized access to sensitive data of the site, and this information can be used for nefarious purposes.

When exploited, the CVE-2021-39327 vulnerability can lead to several serious consequences. Attackers can gain access to sensitive user information, website data, financial records, and other valuable assets related to the website. This can result in financial loss for the site owner, as well as reputational damage. Attackers may also use this sensitive information to launch additional attacks against other websites or users.

Thanks to the pro features of the s4e.io platform, site owners can easily and quickly learn about vulnerabilities in their digital assets. The platform provides real-time security monitoring, vulnerability assessments, and threat intelligence reports. With this knowledge, site owners can take proactive steps to secure their website and protect their digital assets from cyber attacks.

 

REFERENCES

Solution Advice

To protect against the CVE-2021-39327 vulnerability in the BulletProof Security plugin, site owners can take the following precautions:

  • Immediately update to the latest version of the plugin.
  • Disable public access to the ~/db_backup_log.txt file.
  • Implement proper access controls and permissions for sensitive data.
  • Monitor the site for suspicious activity and unauthorized access attempts.
  • Regularly backup website data and store it in a secure location.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2021-39327 scanner - Information Disclosure vulnerability in BulletProof Security plugin for WordPress | S4E