CVE Feed

    Dashboard / CVE / CVE-2009-2334

    CVE-2009-2334

    wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.

    Published:Jul 8, 2009
    Last Modified:Apr 23, 2026
    EPS:Jul 10, 2009
    EPSS Score:0.12303
    CVSS Score:4.9

    Affected Products

    Vendor
    Wordpress
    Product
    Wordpress
    Vendor
    Wordpress
    Product
    Wordpress Mu

    Common Weakness Enumeration

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High