WordPress 2.2.x and 2.3.x allows remote attackers to obtain sensitive information via an invalid p parameter in an rss2 action to the default URI, which reveals the full path and the SQL database structure.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.026
EPSS Ranking 83.2%