CVE-2009-2336
WordPress <2.8.1 - Info Disclosure
Title source: llmDescription
The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
Exploits (1)
exploitdb
WRITEUP
VERIFIED
by Core Security · textwebappsphp
https://www.exploit-db.com/exploits/9110
References (11)
Scores
EPSS
0.0230
EPSS Percentile
84.5%
Classification
CWE
CWE-16
Status
draft
Affected Products (2)
wordpress/wordpress
< 2.8.1
wordpress/wordpress_mu
< 2.8.1
Timeline
Published
Jul 10, 2009
Tracked Since
Feb 18, 2026