CVE-2009-2762
WordPress <2.8.3 - Auth Bypass
Title source: llmDescription
wp-login.php in WordPress 2.8.3 and earlier allows remote attackers to force a password reset for the first user in the database, possibly the administrator, via a key[] array variable in a resetpass (aka rp) action, which bypasses a check that assumes that $key is not an array.
Exploits (3)
exploitdb
WRITEUP
VERIFIED
by laurent gaffié · textwebappsphp
https://www.exploit-db.com/exploits/9410
exploitdb
WORKING POC
VERIFIED
by iso^kpsbr · phpwebappsphp
https://www.exploit-db.com/exploits/6421
References (8)
Scores
EPSS
0.7413
EPSS Percentile
98.8%
Details
CWE
CWE-255
Status
published
Products (1)
wordpress/wordpress
< 2.8.3
Published
Aug 13, 2009
Tracked Since
Feb 18, 2026