CVE-2009-2431

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
10/07/2009
Last modified:
10/10/2018

Description

WordPress 2.7.1 places the username of a post's author in an HTML comment, which allows remote attackers to obtain sensitive information by reading the HTML source.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wordpress:wordpress:2.7.1:*:*:*:*:*:*:*