CVE-2007-1409: Medium severity WordPress vulnerability
Published Mar 10, 2007
·Updated
WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.
Affected Software
10 affected components
WordPress=2.0
WordPress=2.0.1
WordPress=2.0.2
WordPress=2.0.3
WordPress=2.0.4
WordPress=2.0.5
WordPress=2.0.6
WordPress=2.0.7
WordPress=2.1
WordPress=2.1.1
Event History
Mar 10, 2007
CVE Published
10:19 PM
Mar 11, 2007
CVE Published
via MITRE·03:00 AM
Data Sourced
via MITRE·03:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1409?
CVE-2007-1409 has a medium severity rating due to the potential exposure of sensitive information.
2
How does CVE-2007-1409 affect WordPress installations?
CVE-2007-1409 allows remote attackers to access sensitive paths in error messages by directly requesting specific PHP files.
3
How do I fix CVE-2007-1409?
To address CVE-2007-1409, it is recommended to upgrade WordPress to the latest version available.
4
Which versions of WordPress are affected by CVE-2007-1409?
CVE-2007-1409 affects WordPress versions 2.0 through 2.1.1.
5
Is it possible to mitigate CVE-2007-1409 without upgrading?
Mitigating CVE-2007-1409 without upgrading is generally not advisable as the best solution is to patch by upgrading to a newer version of WordPress.