Oh, it is good.
https://twitter.com/hashtag/ParlerLeaks
https://twitter.com/hashtag/parlerhack
Post any good finds.
Best explanation I've seen why this is a big deal.
WordPress Config file being accessible is a big yikes. Gives you the destination for the DB as well as the username and password to sign into it. MySQL export and anything not using MD5 Hash is visible right away - the rest? Decrypt.
Soon as the DB has been exported, game over.
https://twitter.com/IckleIzu/status/1331401417186299909
They hardcoded the salted passwords next to the key. It would be like posting a physical key on a locked door.
My friend teaches C+ at a community college and he would fail whatever monkey wrote this code.