CVE-2009-2335
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 85.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 85.00% probability · 100th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-16
- Affected
- wordpress/wordpress · wordpress/wordpress mu
- Source
- cve@mitre.org
References
- http://corelabs.coresecurity.com/index.php?action=view&type=advisory&name=WordPress_Privileges_UncheckedExploit, Third Party Advisory
- http://securitytracker.com/id?1022528Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/9110Third Party Advisory, VDB Entry
- http://www.osvdb.org/55713Broken Link
- http://www.securityfocus.com/archive/1/504795/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35581Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/1833Patch, Vendor Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00597.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00608.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00632.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00676.htmlThird Party Advisory
- http://corelabs.coresecurity.com/index.php?action=view&type=advisory&name=WordPress_Privileges_UncheckedExploit, Third Party Advisory
- http://securitytracker.com/id?1022528Third Party Advisory, VDB Entry
- http://www.exploit-db.com/exploits/9110Third Party Advisory, VDB Entry
- http://www.osvdb.org/55713Broken Link
- http://www.securityfocus.com/archive/1/504795/100/0/threadedThird Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/35581Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2009/1833Patch, Vendor Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00597.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00608.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00632.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00676.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.