ProjectDiscovery received pull requests adding new Nuclei detection templates for CVE-2023-7165 and CVE-2023-6592, both covering information disclosure flaws in WordPress components that expose sensitive directories over HTTP. The CVE-2023-7165 template identified publicly accessible JetBackup files under /wp-content/uploads/jetbackup/, where directory listing was enabled and backup artifacts included a SQL database dump and wp-config.php. Validation output showed successful detection on a live target returning 200 OK, highlighting the risk of attackers retrieving full site backups and configuration data.
A second template for CVE-2023-6592 targeted the FastDup plugin, detecting an exposed logs directory at /wp-content/plugins/fastdup/logs/ with directory indexing enabled and a visible fastdup_log.txt file. The contributor reported testing against both vulnerable and patched setups to limit false positives, while ProjectDiscovery’s automated review found no security issues in either template itself, though it flagged metadata inconsistencies in the FastDup submission such as mismatched search dorks and an inaccurate request count.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A Nuclei template for CVE-2023-7165 was created and validated against a WordPress site exposing /wp-content/uploads/jetbackup/ with directory listing enabled. The accessible backup directory contained sensitive artifacts including a SQL dump and wp-config.php, demonstrating high-severity information disclosure.
A Nuclei template for CVE-2023-6592 was created and validated against a WordPress FastDup plugin exposure where /wp-content/plugins/fastdup/logs/ returned HTTP 200 with directory listing enabled and a visible fastdup_log.txt file. The contributor said the template was tested against both vulnerable and patched configurations to reduce false positives.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.