WordPress and WordPress MU (versions before 2.8.1) have a security vulnerability that allows attackers to get access to sensitive information. The vulnerability can be exploited by sending a direct request to a specific file (wp-settings.php) which will then reveal the path of the WordPress installation in an error message.