CVE-2011-3818

WordPress 2.9.2 and 3.0.4 - Exposure of Sensitive Information via Direct Request to .php Files

Title source: llm
STIX 2.1

Description

WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.

References (3)

Core 3

Scores

EPSS 0.0050
EPSS Percentile 66.1%

Details

CWE
CWE-200
Status published
Products (2)
wordpress/wordpress 2.9.2
wordpress/wordpress 3.0.4
Published Sep 24, 2011
Tracked Since Feb 18, 2026