Vulnerability Description
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wordpress | Wordpress | < 2.8.1 |
| Wordpress | Wordpress Mu | < 2.8.1 |
Related Weaknesses (CWE)
References
- http://corelabs.coresecurity.com/index.php?action=view&type=advisory&name=WordPrExploitPatchThird Party Advisory
- http://securitytracker.com/id?1022528PatchThird Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/9110Third Party AdvisoryVDB Entry
- http://www.osvdb.org/55714Broken LinkPatch
- http://www.securityfocus.com/archive/1/504795/100/0/threadedThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/35581Third Party AdvisoryVDB Entry
- http://www.vupen.com/english/advisories/2009/1833PatchThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00597.htmThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00608.htmThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00632.htmlThird Party Advisory
- https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00676.htmlThird Party Advisory
- http://corelabs.coresecurity.com/index.php?action=view&type=advisory&name=WordPrExploitPatchThird Party Advisory
- http://securitytracker.com/id?1022528PatchThird Party AdvisoryVDB Entry
- http://www.exploit-db.com/exploits/9110Third Party AdvisoryVDB Entry
- http://www.osvdb.org/55714Broken LinkPatch
FAQ
What is CVE-2009-2336?
CVE-2009-2336 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers t...
How severe is CVE-2009-2336?
CVE-2009-2336 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2009-2336?
Check the references section above for vendor advisories and patch information. Affected products include: Wordpress Wordpress, Wordpress Wordpress Mu.