PT-2026-41463 · Gotmls · Anti-Malware Security/Brute-Force Firewall
Thesmuggler
·
Published
2026-05-16
·
Updated
2026-05-16
·
CVE-2021-47977
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
WordPress Plugin Anti-Malware Security and Bruteforce Firewall 4.20.59 contains a directory traversal vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the file parameter. Attackers can send requests to the duplicator download action via admin-ajax.php with path traversal sequences to access sensitive system files outside the intended directory.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Anti-Malware Security/Brute-Force Firewall