5
CVSSv2

CVE-2010-4403

Published: 06/12/2010 Updated: 10/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The Register Plus plugin 3.5.1 and previous versions for WordPress allows remote malicious users to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.

Vulnerable Product Search on Vulmon Subscribe to Product

devbits register-plus 3.4

devbits register-plus 3.3

devbits register-plus 2.7

devbits register-plus 2.6

devbits register-plus 1.2

devbits register-plus 1.1

devbits register-plus 3.5

devbits register-plus 3.4.1

devbits register-plus 3.0

devbits register-plus 2.9

devbits register-plus 2.8

devbits register-plus 2.1

devbits register-plus 2.0

devbits register-plus 3.2

devbits register-plus 3.1

devbits register-plus 2.5

devbits register-plus 2.4

devbits register-plus

devbits register-plus 3.0.2

devbits register-plus 3.0.1

devbits register-plus 2.3

devbits register-plus 2.2