PT-2009-4848 · WordPress · Wordpress

Published

2009-07-10

·

Updated

2018-10-10

·

CVE-2009-2431

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions WordPress version 2.7.1
Description The issue allows remote attackers to obtain sensitive information by reading the HTML source, specifically the username of a post's author, which is placed in an HTML comment.
Recommendations For WordPress version 2.7.1, consider updating to a newer version that does not include this sensitive information in HTML comments, or manually remove the username from the HTML source to prevent information disclosure.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-2431

Affected Products

Wordpress