Unrated severityNVD Advisory· Published Jul 10, 2009· Updated Jun 16, 2026
CVE-2009-2335
CVE-2009-2335
Description
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*range: <2.8.1
- cpe:2.3:a:wordpress:wordpress_mu:*:*:*:*:*:*:*:*range: <2.8.1
- (no CPE)range: <2.8.1
- Range: <2.8.1
Patches
Vulnerability mechanics
References
11- www.vupen.com/english/advisories/2009/1833nvdPatchVendor Advisory
- corelabs.coresecurity.com/index.phpnvdExploitThird Party Advisory
- securitytracker.com/idnvdThird Party AdvisoryVDB Entry
- www.exploit-db.com/exploits/9110nvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/504795/100/0/threadednvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/35581nvdThird Party AdvisoryVDB Entry
- www.redhat.com/archives/fedora-package-announce/2009-August/msg00597.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-August/msg00608.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00632.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00676.htmlnvdThird Party Advisory
- www.osvdb.org/55713nvdBroken Link
News mentions
0No linked articles in our index yet.