Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).
CVE-2009-2334 — Improper Authentication in Wordpress
Severity
4.9MEDIUMNVD
EPSS
12.3%
top 6.10%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedJul 10
Latest updateMay 2
Description
wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: thi…
CVSS vector
AV:N/AC:M/C:P/I:P/A:NExploitability: 6.8 | Impact: 4.9
Affected Packages4 packages
Patches
🔴Vulnerability Details
2💥Exploits & PoCs
1Exploit-DB▶
WordPress Core / MU / Plugins - '/admin.php' Privileges Unchecked / Multiple Information Disclosures↗2009-07-10
🔍Detection Rules
1Suricata▶
ET WEB_SPECIFIC_APPS WordPress wp-admin/admin.php Module Configuration Security Bypass Attempt↗2010-07-30
📋Vendor Advisories
2💬Community
1Bugzilla▶
CORE-2009-0515, CVE-2009-2334, CVE-2009-2335, CVE-2009-2336 CVE-2009-2431, CVE-2009-2432 wordpress: multiple vulnerabilities↗2009-07-10