WordPress WPEngine Configuration Detected

medium Web App Scanning Plugin ID 114091

Synopsis

WordPress WPEngine Configuration Detected

Description

WPengine is a popular provider of managed WordPress hosting. Configurations may be located in a file named config.json inside the _wpeprivate hidden directory. This configuration file may expose sensitive information such as database credentials and WPEngine account information which may be used by an attacker to gain unauthorized access.

Solution

Review the WPE Security settings and remove the _wpeprivate/ directory from public view, and/or adjust the web server's access controls to limit access to this directory.

See Also

https://wpengine.com/support/wp-engines-security-environment/

Plugin Details

Severity: Medium

ID: 114091

Type: remote

Published: 10/25/2023

Updated: 10/25/2023

Scan Template: api, basic, full, pci, scan

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS Score Source: Tenable

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

CVSS Score Source: Tenable

CVSS v4

Risk Factor: Medium

Base Score: 6.9

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CVSS Score Source: Tenable

Reference Information