CVE-2008-2146

WordPress < 2.2.3 - Unauthenticated Access Restriction Bypass via PATH_INFO Handling

Title source: llm
STIX 2.1

Description

wp-includes/vars.php in Wordpress before 2.2.3 does not properly extract the current path from the PATH_INFO ($PHP_SELF), which allows remote attackers to bypass intended access restrictions for certain pages.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/45188
Patch x_refsource_confirm
http://trac.wordpress.org/ticket/4748
Exploit x_refsource_confirm
http://trac.wordpress.org/changeset/6029
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/42379

Scores

EPSS 0.0058
EPSS Percentile 69.2%

Details

CWE
CWE-264
Status published
Products (47)
wordpress/wordpress 0.6.2
wordpress/wordpress 0.6.2.1
wordpress/wordpress 0.7
wordpress/wordpress 0.71
wordpress/wordpress 0.711
wordpress/wordpress 1.0
wordpress/wordpress 1.0.1
wordpress/wordpress 1.0.2
wordpress/wordpress 1.2
wordpress/wordpress 1.2.1
... and 37 more
Published May 12, 2008
Tracked Since Feb 18, 2026