WordPress True Ranker before version 2.2.4 allows sensitive configuration files such as wp-config.php, to be accessed via the src parameter found in the ~/admin/vendor/datatables/examples/resources/examples.php file via local file inclusion.
View the template here CVE-2021-39312.yaml
References:
https://github.com/ARPSyndicate/cvemon