CVE-2009-2334

WordPress < 2.8.1 - Unauthenticated Sensitive Information Exposure via Plugin Configuration

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2009-2334. PoCs published by Core Security.

AI-analyzed exploit summary This advisory details multiple vulnerabilities in WordPress, including privilege escalation via unchecked access to plugin configuration pages and information disclosure. It provides technical analysis of the root cause and proof-of-concept URLs demonstrating the flaws.

Description

wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.

Exploits (1)

exploitdb WRITEUP VERIFIED
by Core Security · textwebappsphp
https://www.exploit-db.com/exploits/9110

This advisory details multiple vulnerabilities in WordPress, including privilege escalation via unchecked access to plugin configuration pages and information disclosure. It provides technical analysis of the root cause and proof-of-concept URLs demonstrating the flaws.

Classification
Writeup 100%
Attack Type
Auth Bypass | Info Leak | Xss
Complexity
Moderate
Reliability
Reliable
Target: WordPress 2.8 and previous, WordPress MU 2.7.1 and previous
Auth required
Prerequisites: Access to a WordPress instance with vulnerable version · Subscriber-level account or higher
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (14)

Core 14
Core References
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00676.html
Vendor Advisory x_refsource_confirm
http://wordpress.org/development/2009/07/wordpress-2-8-1/
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/504795/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1022528
Vendor Advisory vendor-advisory x_refsource_fedora
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00632.html
Patch, Vendor Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1833
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2009/dsa-1871
Exploit, Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/55712
Exploit, Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/35584
Patch vdb-entry x_refsource_osvdb
http://www.osvdb.org/55715
Exploit, Third Party Advisory exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/9110

Scores

EPSS 0.0626
EPSS Percentile 92.7%

Details

CWE
CWE-287
Status published
Products (40)
wordpress/wordpress 0.6.2 (2 CPE variants)
wordpress/wordpress 0.6.2.1 (2 CPE variants)
wordpress/wordpress 0.7
wordpress/wordpress 0.71
wordpress/wordpress 0.71-gold
wordpress/wordpress 0.72 (4 CPE variants)
wordpress/wordpress 0.711
wordpress/wordpress 1.0 (5 CPE variants)
wordpress/wordpress 1.0-platinum
wordpress/wordpress 1.0.1
... and 30 more
Published Jul 10, 2009
Tracked Since Feb 18, 2026