Unrated severityNVD Advisory· Published Jul 10, 2009· Updated Apr 23, 2026
CVE-2009-2336
CVE-2009-2336
Description
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
Affected products
2- cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:*Range: <2.8.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
11- securitytracker.com/idnvdPatchThird Party AdvisoryVDB Entry
- www.osvdb.org/55714nvdBroken LinkPatch
- www.vupen.com/english/advisories/2009/1833nvdPatchThird Party Advisory
- corelabs.coresecurity.com/index.phpnvdExploitPatchThird Party Advisory
- www.exploit-db.com/exploits/9110nvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/archive/1/504795/100/0/threadednvdThird Party AdvisoryVDB Entry
- www.securityfocus.com/bid/35581nvdThird Party AdvisoryVDB Entry
- www.redhat.com/archives/fedora-package-announce/2009-August/msg00597.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-August/msg00608.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00632.htmlnvdThird Party Advisory
- www.redhat.com/archives/fedora-package-announce/2009-July/msg00676.htmlnvdThird Party Advisory
News mentions
0No linked articles in our index yet.