CVE-2009-2336

Source
https://cve.org/CVERecord?id=CVE-2009-2336
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2009-2336.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2009-2336
Downstream
Published
2009-07-10T21:00:00Z
Modified
2026-04-10T03:40:48.393841Z
Summary
[none]
Details

The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."

References

Affected packages