The forgotten mail interface in WordPress and WordPress MU before 2.8.1 exhibits different behavior for a password request depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for user convenience.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Wordpress | Wordpress | * | 2.8.1 (excluding) |
Wordpress_mu | Wordpress | * | 2.8.1 (excluding) |
Wordpress | Ubuntu | dapper | * |
Wordpress | Ubuntu | hardy | * |
Wordpress | Ubuntu | intrepid | * |
Wordpress | Ubuntu | jaunty | * |
Wordpress | Ubuntu | upstream | * |