First published: Fri Jul 10 2009(Updated: )
WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress | =2.7.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-2431 is classified as moderate due to exposure of sensitive information.
To fix CVE-2009-2431, upgrade to a newer version of WordPress that does not expose the author's username in HTML comments.
CVE-2009-2431 specifically affects WordPress version 2.7.1.
CVE-2009-2431 is an information disclosure vulnerability that allows attackers to read sensitive information from the HTML source.
Yes, CVE-2009-2431 can be exploited remotely by attackers to obtain sensitive information.