Vulnerability record · CVE-2009-2335 · published 10 July 2009
CVE-2009-2335: WordPress login error message enables username enumeration
Wordpress · Wordpress
WordPress and WordPress MU before 2.8.1 return different responses for failed logins depending on whether the supplied username exists, letting a remote attacker distinguish valid accounts from invalid ones. The vendor reportedly disputes the significance, calling the behavior a user-convenience feature, so it may remain unfixed in some deployments. It matters because a confirmed username list is a prerequisite for targeted password guessing against WordPress authentication.
Description
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
medium priorityThe flaw only leaks username validity, but it is trivially reachable unauthenticated and has very high EPSS, making it a useful reconnaissance step before credential attacks.
What it is
WordPress and WordPress MU before 2.8.1 return different responses for failed logins depending on whether the supplied username exists, letting a remote attacker distinguish valid accounts from invalid ones. The vendor reportedly disputes the significance, calling the behavior a user-convenience feature, so it may remain unfixed in some deployments. It matters because a confirmed username list is a prerequisite for targeted password guessing against WordPress authentication.
Impact
An attacker gains a verified list of valid WordPress usernames, which narrows brute-force and credential-stuffing attempts to real accounts. No data, code execution or privilege is obtained directly from this flaw.
Attack surface
Reachable remotely over the network through the standard WordPress login form or XML-RPC authentication endpoint; no authentication is required and no user interaction is needed. The CVSS 2.0 vector AV:N/AC:L/Au:N/C:P/I:N/A:N confirms unauthenticated network access with partial confidentiality impact only.
Exploitation
Not listed in CISA KEV, but EPSS is 0.85 (99.7th percentile), indicating a high modeled likelihood of exploitation activity. References carry Exploit and Third Party Advisory tags, including an Exploit-DB entry, so public proof-of-concept tooling exists.
What to do
- Upgrade WordPress and WordPress MU to 2.8.1 or later, or apply the vendor patch referenced in the advisory.
- If upgrade is not possible, normalize login failure responses so valid and invalid usernames produce identical messages, timing and status codes.
- Add rate limiting, CAPTCHA or temporary lockout on the login and XML-RPC authentication endpoints to blunt username enumeration and follow-on guessing.
- Disable or restrict XML-RPC authentication where it is not required.
- Monitor authentication logs for high-volume failed logins from single sources and block offending addresses.
Detection
- Alert on bursts of failed login attempts from a single IP or user agent against wp-login.php or xmlrpc.php.
- Compare response size, body text and status codes for failed logins with known-valid versus known-invalid usernames to confirm the enumeration difference.
- Correlate enumeration-style failed logins with subsequent successful authentication from the same source.
- Review web logs for automated scanning of login endpoints and for user-agent strings matching public enumeration tools.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-2335 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-2335), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.