Wordpress Alert: Exposed wp-config.php backups
A copied configuration file is served as plain text from the web root. Database credentials and security keys may leak.
What it looks like
A copied configuration file is served as plain text from the web root.
Why it matters
Database credentials and security keys may leak.
What to check
Look for leftover configuration copies and restrict file access.
Documentation
This is an exploit pattern to check in installed components, not a claim that every WordPress site has this flaw. Confirm the product and version against its advisories before treating a site as affected. See WordPress hardening guide.
- Categories: WordPress
- Tags: #WordPress Security, #Hosting Security