id: wordpress-affiliatewp-log info: name: WordPress Plugin "AffiliateWP -- Allowed Products" Log Disclosure author: dhiyaneshDK severity: low description: Exposed debug log in AffiliateWP Wordpress Plugin metadata: max-request: 1 tags: wordpress,log,plugin http: - method: GET path: - '{{BaseURL}}/wp-content/uploads/affwp-debug.log' matchers-condition: and matchers: - type: word words: - 'Referral could not be retrieved' - 'Affiliate CSV' - type: word words: - 'text/plain' part: header - type: status status: - 200 # digest: 4b0a00483046022100cfc76a420053c4979d2417bee24276c18f0d206a55ed9aabafee65b1d95f5d89022100f0490c322d3906450953ca3ee5afe5912320454f66c5c59311c0cd087ef221ad:922c64590222798bb761d5b6d8e72950