Vulnerability Database

289,697

Total vulnerabilities in the database

CVE-2009-2334

wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.

  • Published: Jul 10, 2009
  • Updated: Apr 13, 2023
  • CVE: CVE-2009-2334
  • Severity: Low
  • Exploit:

CVSS v2:

  • Severity: Low
  • Score: 4.9
  • AV:N/AC:M/Au:S/C:P/I:P/A:N
Software From Fixed in
WordPress / wordpress 2.0.11 2.0.11.x
WordPress / wordpress 1.2-mingus 1.2-mingus.x
WordPress / wordpress 2.3.1-rc1 2.3.1-rc1.x
WordPress / wordpress 2.0 2.0.x
WordPress / wordpress 2.1.1 2.1.1.x
WordPress / wordpress 2.1.3_rc2 2.1.3_rc2.x
WordPress / wordpress 2.2.3 2.2.3.x
WordPress / wordpress 2.0.2 2.0.2.x
WordPress / wordpress_mu 1.5.1 1.5.1.x
WordPress / wordpress 1.2-beta 1.2-beta.x
WordPress / wordpress_mu 1.3.3 1.3.3.x
WordPress / wordpress 2.1 2.1.x
WordPress / wordpress 2.1-alpha_3 2.1-alpha_3.x
WordPress / wordpress 2.0.10_rc1 2.0.10_rc1.x
WordPress / wordpress 1.5-strayhorn 1.5-strayhorn.x
WordPress / wordpress 1.2-delta 1.2-delta.x
WordPress / wordpress 2.0.6 2.0.6.x
WordPress / wordpress 1.0-rc2 1.0-rc2.x
WordPress / wordpress 2.0.1 2.0.1.x
WordPress / wordpress 2.0.4 2.0.4.x
WordPress / wordpress 1.3.1 1.3.1.x
WordPress / wordpress_mu 2.6.3 2.6.3.x
WordPress / wordpress_mu 2.6 2.6.x
WordPress / wordpress_mu 1.2.5a 1.2.5a.x
WordPress / wordpress 0.6.2.1-beta_2 0.6.2.1-beta_2.x
WordPress / wordpress 0.71-gold 0.71-gold.x
WordPress / wordpress_mu 1.2.3 1.2.3.x
WordPress / wordpress_mu 2.6.1 2.6.1.x
WordPress / wordpress 2.2_revision5003 2.2_revision5003.x
WordPress / wordpress 0.711 0.711.x
WordPress / wordpress 0.6.2.1 0.6.2.1.x
WordPress / wordpress 1.4 1.4.x
WordPress / wordpress 2.2 2.2.x
WordPress / wordpress 1.2.1 1.2.1.x
WordPress / wordpress 0.7 0.7.x
WordPress / wordpress 2.1.3 2.1.3.x
WordPress / wordpress 0.72-beta2 0.72-beta2.x
WordPress / wordpress 2.0.7 2.0.7.x
WordPress / wordpress_mu 1.3.2 1.3.2.x
WordPress / wordpress 2.2.0 2.2.0.x
WordPress / wordpress 2.1.2 2.1.2.x
WordPress / wordpress 0.71 0.71.x
WordPress / wordpress 2.6.3 2.6.3.x
WordPress / wordpress 1.0-rc4 1.0-rc4.x
WordPress / wordpress 2.0.5 2.0.5.x
WordPress / wordpress 1.0-rc3 1.0-rc3.x
WordPress / wordpress_mu 1.2 1.2.x
WordPress / wordpress 2.6.5 2.6.5.x
WordPress / wordpress 0.6.2 0.6.2.x
WordPress / wordpress 2.2.2 2.2.2.x
WordPress / wordpress 2.3.3 2.3.3.x
WordPress / wordpress 1.5.1.1 1.5.1.1.x
WordPress / wordpress 2.0.9 2.0.9.x
WordPress / wordpress_mu 1.1 1.1.x
WordPress / wordpress_mu 1.2.2 1.2.2.x
WordPress / wordpress 2.2.1 2.2.1.x
WordPress / wordpress_mu 1.2.4-rc1 1.2.4-rc1.x
WordPress / wordpress 1.5.2 1.5.2.x
WordPress / wordpress_mu 1.3 1.3.x
WordPress / wordpress 1.6 1.6.x
WordPress / wordpress 1.0.1 1.0.1.x
WordPress / wordpress_mu 1.3.1 1.3.1.x
WordPress / wordpress 2.0.10_rc2 2.0.10_rc2.x
WordPress / wordpress 0.72 0.72.x
WordPress / wordpress 1.0.2-blakey 1.0.2-blakey.x
WordPress / wordpress 2.3.1 2.3.1.x
WordPress / wordpress 1.0.2 1.0.2.x
WordPress / wordpress 2.5.1 2.5.1.x
WordPress / wordpress 1.0-rc1 1.0-rc1.x
WordPress / wordpress 2.0.3 2.0.3.x
WordPress / wordpress 2.6.1 2.6.1.x
WordPress / wordpress 1.5.1.2 1.5.1.2.x
WordPress / wordpress 0.72-rc1 0.72-rc1.x
WordPress / wordpress 1.2 1.2.x
WordPress / wordpress 2.3-beta3 2.3-beta3.x
WordPress / wordpress 2.5 2.5.x
WordPress / wordpress 2.1.3_rc1 2.1.3_rc1.x
WordPress / wordpress 1.0-platinum 1.0-platinum.x
WordPress / wordpress_mu 1.1.1 1.1.1.x
WordPress / wordpress - 2.7.1.x
WordPress / wordpress 1.2.2 1.2.2.x
WordPress / wordpress_mu 2.6.2 2.6.2.x
WordPress / wordpress 2.0.10 2.0.10.x
WordPress / wordpress 1.0.1-miles 1.0.1-miles.x
WordPress / wordpress 1.0 1.0.x
WordPress / wordpress_mu 1.5-rc1 1.5-rc1.x
WordPress / wordpress_mu 1.2.1 1.2.1.x
WordPress / wordpress 1.5 1.5.x
WordPress / wordpress_mu 2.6.5 2.6.5.x
WordPress / wordpress 1.5.1 1.5.1.x
WordPress / wordpress 0.6.2-beta_2 0.6.2-beta_2.x
WordPress / wordpress 1.5.1.3 1.5.1.3.x
WordPress / wordpress 2.3-rc1 2.3-rc1.x
WordPress / wordpress_mu - 2.7.x
WordPress / wordpress 2.3.2 2.3.2.x
WordPress / wordpress 0.72-beta1 0.72-beta1.x
WordPress / wordpress 2.6 2.6.x
WordPress / wordpress_mu 1.2.4 1.2.4.x
WordPress / wordpress 2.2_revision5002 2.2_revision5002.x
WordPress / wordpress 2.0.8 2.0.8.x
WordPress / wordpress 2.3 2.3.x