CVE Vulnerabilities

CVE-2009-2334

Improper Authentication

Published: Jul 10, 2009 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.9 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

wp-admin/admin.php in WordPress and WordPress MU before 2.8.1 does not require administrative authentication to access the configuration of a plugin, which allows remote attackers to specify a configuration file in the page parameter to obtain sensitive information or modify this file, as demonstrated by the (1) collapsing-archives/options.txt, (2) akismet/readme.txt, (3) related-ways-to-take-action/options.php, (4) wp-security-scan/securityscan.php, and (5) wp-ids/ids-admin.php files. NOTE: this can be leveraged for cross-site scripting (XSS) and denial of service.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
WordpressWordpress*2.7.1 (including)
WordpressWordpress0.6.2 (including)0.6.2 (including)
WordpressWordpress0.6.2-beta_2 (including)0.6.2-beta_2 (including)
WordpressWordpress0.6.2.1 (including)0.6.2.1 (including)
WordpressWordpress0.6.2.1-beta_2 (including)0.6.2.1-beta_2 (including)
WordpressWordpress0.7 (including)0.7 (including)
WordpressWordpress0.71 (including)0.71 (including)
WordpressWordpress0.71-gold (including)0.71-gold (including)
WordpressWordpress0.72 (including)0.72 (including)
WordpressWordpress0.72-beta1 (including)0.72-beta1 (including)
WordpressWordpress0.72-beta2 (including)0.72-beta2 (including)
WordpressWordpress0.72-rc1 (including)0.72-rc1 (including)
WordpressWordpress0.711 (including)0.711 (including)
WordpressWordpress1.0 (including)1.0 (including)
WordpressWordpress1.0-rc1 (including)1.0-rc1 (including)
WordpressWordpress1.0-rc2 (including)1.0-rc2 (including)
WordpressWordpress1.0-rc3 (including)1.0-rc3 (including)
WordpressWordpress1.0-rc4 (including)1.0-rc4 (including)
WordpressWordpress1.0-platinum (including)1.0-platinum (including)
WordpressWordpress1.0.1 (including)1.0.1 (including)
WordpressWordpress1.0.1-miles (including)1.0.1-miles (including)
WordpressWordpress1.0.2 (including)1.0.2 (including)
WordpressWordpress1.0.2-blakey (including)1.0.2-blakey (including)
WordpressWordpress1.2 (including)1.2 (including)
WordpressWordpress1.2-beta (including)1.2-beta (including)
WordpressWordpress1.2-delta (including)1.2-delta (including)
WordpressWordpress1.2-mingus (including)1.2-mingus (including)
WordpressWordpress1.2.1 (including)1.2.1 (including)
WordpressWordpress1.2.2 (including)1.2.2 (including)
WordpressWordpress1.3.1 (including)1.3.1 (including)
WordpressWordpress1.4 (including)1.4 (including)
WordpressWordpress1.5 (including)1.5 (including)
WordpressWordpress1.5-strayhorn (including)1.5-strayhorn (including)
WordpressWordpress1.5.1 (including)1.5.1 (including)
WordpressWordpress1.5.1.1 (including)1.5.1.1 (including)
WordpressWordpress1.5.1.2 (including)1.5.1.2 (including)
WordpressWordpress1.5.1.3 (including)1.5.1.3 (including)
WordpressWordpress1.5.2 (including)1.5.2 (including)
WordpressWordpress1.6 (including)1.6 (including)
WordpressWordpress2.0 (including)2.0 (including)
WordpressWordpress2.0.1 (including)2.0.1 (including)
WordpressWordpress2.0.2 (including)2.0.2 (including)
WordpressWordpress2.0.3 (including)2.0.3 (including)
WordpressWordpress2.0.4 (including)2.0.4 (including)
WordpressWordpress2.0.5 (including)2.0.5 (including)
WordpressWordpress2.0.6 (including)2.0.6 (including)
WordpressWordpress2.0.7 (including)2.0.7 (including)
WordpressWordpress2.0.8 (including)2.0.8 (including)
WordpressWordpress2.0.9 (including)2.0.9 (including)
WordpressWordpress2.0.10 (including)2.0.10 (including)
WordpressWordpress2.0.10_rc1 (including)2.0.10_rc1 (including)
WordpressWordpress2.0.10_rc2 (including)2.0.10_rc2 (including)
WordpressWordpress2.0.11 (including)2.0.11 (including)
WordpressWordpress2.1 (including)2.1 (including)
WordpressWordpress2.1-alpha_3 (including)2.1-alpha_3 (including)
WordpressWordpress2.1.1 (including)2.1.1 (including)
WordpressWordpress2.1.2 (including)2.1.2 (including)
WordpressWordpress2.1.3 (including)2.1.3 (including)
WordpressWordpress2.1.3_rc1 (including)2.1.3_rc1 (including)
WordpressWordpress2.1.3_rc2 (including)2.1.3_rc2 (including)
WordpressWordpress2.2 (including)2.2 (including)
WordpressWordpress2.2.0 (including)2.2.0 (including)
WordpressWordpress2.2.1 (including)2.2.1 (including)
WordpressWordpress2.2.2 (including)2.2.2 (including)
WordpressWordpress2.2.3 (including)2.2.3 (including)
WordpressWordpress2.2_revision5002 (including)2.2_revision5002 (including)
WordpressWordpress2.2_revision5003 (including)2.2_revision5003 (including)
WordpressWordpress2.3 (including)2.3 (including)
WordpressWordpress2.3-beta3 (including)2.3-beta3 (including)
WordpressWordpress2.3-rc1 (including)2.3-rc1 (including)
WordpressWordpress2.3.1 (including)2.3.1 (including)
WordpressWordpress2.3.1-rc1 (including)2.3.1-rc1 (including)
WordpressWordpress2.3.2 (including)2.3.2 (including)
WordpressWordpress2.3.3 (including)2.3.3 (including)
WordpressWordpress2.5 (including)2.5 (including)
WordpressWordpress2.5.1 (including)2.5.1 (including)
WordpressWordpress2.6 (including)2.6 (including)
WordpressWordpress2.6.1 (including)2.6.1 (including)
WordpressWordpress2.6.3 (including)2.6.3 (including)
WordpressWordpress2.6.5 (including)2.6.5 (including)
Wordpress_muWordpress*2.7 (including)
Wordpress_muWordpress1.1 (including)1.1 (including)
Wordpress_muWordpress1.1.1 (including)1.1.1 (including)
Wordpress_muWordpress1.2 (including)1.2 (including)
Wordpress_muWordpress1.2.1 (including)1.2.1 (including)
Wordpress_muWordpress1.2.2 (including)1.2.2 (including)
Wordpress_muWordpress1.2.3 (including)1.2.3 (including)
Wordpress_muWordpress1.2.4 (including)1.2.4 (including)
Wordpress_muWordpress1.2.4-rc1 (including)1.2.4-rc1 (including)
Wordpress_muWordpress1.2.5a (including)1.2.5a (including)
Wordpress_muWordpress1.3 (including)1.3 (including)
Wordpress_muWordpress1.3.1 (including)1.3.1 (including)
Wordpress_muWordpress1.3.2 (including)1.3.2 (including)
Wordpress_muWordpress1.3.3 (including)1.3.3 (including)
Wordpress_muWordpress1.5-rc1 (including)1.5-rc1 (including)
Wordpress_muWordpress1.5.1 (including)1.5.1 (including)
Wordpress_muWordpress2.6 (including)2.6 (including)
Wordpress_muWordpress2.6.1 (including)2.6.1 (including)
Wordpress_muWordpress2.6.2 (including)2.6.2 (including)
Wordpress_muWordpress2.6.3 (including)2.6.3 (including)
Wordpress_muWordpress2.6.5 (including)2.6.5 (including)
WordpressUbuntudapper*
WordpressUbuntuhardy*
WordpressUbuntuintrepid*
WordpressUbuntujaunty*
WordpressUbuntuupstream*

Potential Mitigations

References