CVE-2009-4170
WP-Cumulus Plug-in <1.20 - Info Disclosure
Title source: llmDescription
WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.
Exploits (1)
Scores
EPSS
0.0197
EPSS Percentile
83.3%
Classification
CWE
CWE-200
Status
draft
Affected Products (1)
roytanck/wp-cumulus
Timeline
Published
Dec 02, 2009
Tracked Since
Feb 18, 2026