CVE detail
CVE-2015-9491 — CVE-2015-9491
Published 2019-10-11 · Modified 2026-06-17 · Vendor blessing_premium_responsive_project · Product blessing_premium_responsive · Source nvd
HIGH
severity
CVSS-derived band
0.0307
EPSS probability
exploitation probability, 30d
86.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The ThemeMakers Blessing Premium Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References