ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2009-2335

WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
An official patch is available. Apply the patch as soon as possible.
-
CVSS
0.0
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
Patch StatusOfficial Patch

Change Log
DateSourceChangesScore
2026-07-17metasploitE: P→A0.0 → 0.0
2026-07-17exploitdbE: U→P0.0 → 0.0
2026-07-15cve.orginitial0.0

Affected Software
VendorProductVersion
wordpresswordpress≤ 2.8.1
wordpresswordpress_mu< 2.8.1
Published: 2009-07-10