CVE-2009-2335 describes a username enumeration vulnerability in WordPress and WordPress MU versions prior to 2.8.1, where differing login error messages reveal whether a user account exists. This vulnerability has a CVSS score of 5.0 (medium severity), indicating a network-based attack with low complexity that could lead to partial confidentiality impact by exposing valid usernames. While not listed in CISA's KEV catalog, exploit intelligence shows a Metasploit module exists for brute-force and user enumeration, though there is no evidence of active exploitation, significant community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.1CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress:*:*:*:*:*:*:*:* | ||
< 2.8.1CPE matchmatch criteria | cpe:2.3:a:wordpress:wordpress_mu:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.