CVE
- Id
- 39770
- CVE No.
- CVE-2009-2335
- Status
- Candidate
- Description
- WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
- Phase
- Assigned (20090705)
- Votes
- None (candidate not yet proposed)
- Comments