Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2009-2334Improper Authentication in Wordpress

Severity
4.9MEDIUMNVD
EPSS
12.3%
top 6.10%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedJul 10
Latest updateMay 2

Description

wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: thi

CVSS vector

AV:N/AC:M/C:P/I:P/A:NExploitability: 6.8 | Impact: 4.9

Affected Packages4 packages

debiandebian/wordpress< wordpress 2.8.3-1 (bookworm)
Debianwordpress/wordpress< 2.8.3-1+3
NVDwordpress/wordpress2.7.1+65

Patches

🔴Vulnerability Details

2
GHSA
GHSA-54c4-23hm-v988: wp-admin/admin2022-05-02
OSV
CVE-2009-2334: wp-admin/admin2009-07-10

💥Exploits & PoCs

1
Exploit-DB
WordPress Core / MU / Plugins - '/admin.php' Privileges Unchecked / Multiple Information Disclosures2009-07-10

🔍Detection Rules

1
Suricata
ET WEB_SPECIFIC_APPS WordPress wp-admin/admin.php Module Configuration Security Bypass Attempt2010-07-30

📋Vendor Advisories

2
Red Hat
wordpress: multiple vulnerabilities2009-07-08
Debian
CVE-2009-2334: wordpress - wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require a...2009

💬Community

1
Bugzilla
CORE-2009-0515, CVE-2009-2334, CVE-2009-2335, CVE-2009-2336 CVE-2009-2431, CVE-2009-2432 wordpress: multiple vulnerabilities2009-07-10
CVE-2009-2334 — Improper Authentication in Wordpress | cvebase