AUGUST 4, 2026
Live Feed
Return to register
Case File

CVE-2009-4170

MEDIUM · CVSS 5 EPSS 6.39%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2009-12-02 · Last synced 2026-08-04

Field Assessment

AI analysis pending.

CVE
CVE-2009-4170
Severity
MEDIUM
CVSS
5
EPSS
6.39%
WordPress

Original Filing — NVD Description

WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.