CVE-2010-4403

The Register Plus plugin 3.5.1 and earlier for WordPress allows remote attackers to obtain sensitive information via a direct request to (1) dash_widget.php and (2) register-plus.php, which reveals the installation path in an error message.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
VendorProductVersion
devbitsregister-plus
𝑥
≤ 3.5.1
devbitsregister-plus
1.1
devbitsregister-plus
1.2
devbitsregister-plus
2.0
devbitsregister-plus
2.1
devbitsregister-plus
2.2
devbitsregister-plus
2.3
devbitsregister-plus
2.4
devbitsregister-plus
2.5
devbitsregister-plus
2.6
devbitsregister-plus
2.7
devbitsregister-plus
2.8
devbitsregister-plus
2.9
devbitsregister-plus
3.0
devbitsregister-plus
3.0.1
devbitsregister-plus
3.0.2
devbitsregister-plus
3.1
devbitsregister-plus
3.2
devbitsregister-plus
3.3
devbitsregister-plus
3.4
devbitsregister-plus
3.4.1
devbitsregister-plus
3.5
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
wordpress
maverick
not-affected
lucid
not-affected
karmic
not-affected
hardy
not-affected
dapper
not-affected