疑似Oday
The WordPress SVG Support plugin was detected to have publicly accessible PHP files without ABSPATH protection, which exposed sensitive server path information. Direct access to vendor/composer files triggered PHP fatal errors that revealed the full WordPress filesystem path.
id: wp-svg-support-fpd
info:
name: WordPress SVG Support - Full Path Disclosure
author: pussyca
...