CVE-2009-2432

EPSS 1.1%
Published: 7/10/2009Modified: 5/27/2026
Also known as:DEBIAN-CVE-2009-2432

Description

WordPress and WordPress MU before 2.8.1 allow remote attackers to obtain sensitive information via a direct request to wp-settings.php, which reveals the installation path in an error message.

Affected packages (1)

References (1)