CVE-2007-1409
Publication date 10 March 2007
Last updated 17 July 2025
Ubuntu priority
Description
WordPress allows remote attackers to obtain sensitive information via a direct request for wp-admin/admin-functions.php, which reveals the path in an error message.