Junglewise Threat Intelligence

CVE-2021-47977: WordPress Anti-Malware Security and Bruteforce Firewall directory traversal

CVE-2021-47977 · Severity: high · CVSS 7.5 · Published 2026-05-16

Executive brief

A directory traversal vulnerability exists in the Anti-Malware Security and Bruteforce Firewall plugin for WordPress, which is used to protect websites from malicious scripts and brute-force attacks. An unauthenticated attacker can exploit this flaw to read sensitive system files from the web server. This could lead to the exposure of configuration files, credentials, or other private data, potentially compromising the entire website and its underlying server.

Technical details

A directory traversal vulnerability (CWE-22) exists in the Anti-Malware Security and Bruteforce Firewall plugin for WordPress (versions up to and including 4.20.72). The flaw is located within the 'duplicator_download' action accessible via 'admin-ajax.php'. By manipulating the 'file' parameter with path traversal sequences (e.g., '../../'), an unauthenticated remote attacker can bypass directory restrictions to read arbitrary files on the server. This can be used to retrieve sensitive information such as 'wp-config.php' or system files like '/etc/passwd' or 'win.ini'. A proof-of-concept exploit is publicly available.

Affected products

  • Eli Scheetz (GOTMLS.NET) Anti-Malware Security and Bruteforce Firewall <= 4.20.72

Timeline

  • 2021-07-05: disclosed: Exploit published on Exploit-DB
  • 2026-05-16: advisory: NVD and VulnCheck advisory published

References