WordPress 2.0.11 and earlier allows remote attackers to obtain sensitive information via an empty value of the page parameter to certain PHP scripts under wp-admin/, which reveals the path in various error messages.
Change Log
| Date | Source | Changes | Score |
|---|
| 2026-07-17 | PoC | E: U→P | 0.0 → 0.0 |
| 2026-07-15 | cve.org | initial | 0.0 |
Affected Software
| Vendor | Product | Version |
|---|
| wordpress | wordpress | ≤ 2.0.11 |
Published: 2008-01-10