← Vulnerability feed

Vulnerability record · CVE-2009-2335 · published 10 July 2009

CVE-2009-2335: WordPress login error message enables username enumeration

Wordpress · Wordpress

WordPress and WordPress MU before 2.8.1 return different responses for failed logins depending on whether the supplied username exists, letting a remote attacker distinguish valid accounts from invalid ones. The vendor reportedly disputes the significance, calling the behavior a user-convenience feature, so it may remain unfixed in some deployments. It matters because a confirmed username list is a prerequisite for targeted password guessing against WordPress authentication.

5.0 CVSS 2.0 Medium EPSS 85% · top 0.3% CWE-16 · CWE-16
5.0CVSS 2.0 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
22References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the user account exists, which allows remote attackers to enumerate valid usernames. NOTE: the vendor reportedly disputes the significance of this issue, indicating that the behavior exists for "user convenience."

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

medium priorityThe flaw only leaks username validity, but it is trivially reachable unauthenticated and has very high EPSS, making it a useful reconnaissance step before credential attacks.

What it is

WordPress and WordPress MU before 2.8.1 return different responses for failed logins depending on whether the supplied username exists, letting a remote attacker distinguish valid accounts from invalid ones. The vendor reportedly disputes the significance, calling the behavior a user-convenience feature, so it may remain unfixed in some deployments. It matters because a confirmed username list is a prerequisite for targeted password guessing against WordPress authentication.

Impact

An attacker gains a verified list of valid WordPress usernames, which narrows brute-force and credential-stuffing attempts to real accounts. No data, code execution or privilege is obtained directly from this flaw.

Attack surface

Reachable remotely over the network through the standard WordPress login form or XML-RPC authentication endpoint; no authentication is required and no user interaction is needed. The CVSS 2.0 vector AV:N/AC:L/Au:N/C:P/I:N/A:N confirms unauthenticated network access with partial confidentiality impact only.

Exploitation

Not listed in CISA KEV, but EPSS is 0.85 (99.7th percentile), indicating a high modeled likelihood of exploitation activity. References carry Exploit and Third Party Advisory tags, including an Exploit-DB entry, so public proof-of-concept tooling exists.

What to do

  • Upgrade WordPress and WordPress MU to 2.8.1 or later, or apply the vendor patch referenced in the advisory.
  • If upgrade is not possible, normalize login failure responses so valid and invalid usernames produce identical messages, timing and status codes.
  • Add rate limiting, CAPTCHA or temporary lockout on the login and XML-RPC authentication endpoints to blunt username enumeration and follow-on guessing.
  • Disable or restrict XML-RPC authentication where it is not required.
  • Monitor authentication logs for high-volume failed logins from single sources and block offending addresses.

Detection

  • Alert on bursts of failed login attempts from a single IP or user agent against wp-login.php or xmlrpc.php.
  • Compare response size, body text and status codes for failed logins with known-valid versus known-invalid usernames to confirm the enumeration difference.
  • Correlate enumeration-style failed logins with subsequent successful authentication from the same source.
  • Review web logs for automated scanning of login endpoints and for user-agent strings matching public enumeration tools.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://corelabs.coresecurity.com/index.php?action=view&type=advisory&name=WordPress_Privileges_Unchecked ExploitThird Party Advisory
http://securitytracker.com/id?1022528 Third Party AdvisoryVDB Entry
http://www.exploit-db.com/exploits/9110 Third Party AdvisoryVDB Entry
http://www.osvdb.org/55713 Broken Link
http://www.securityfocus.com/archive/1/504795/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/35581 Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2009/1833 PatchVendor Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00597.html Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00608.html Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00632.html Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00676.html Third Party Advisory
http://corelabs.coresecurity.com/index.php?action=view&type=advisory&name=WordPress_Privileges_Unchecked ExploitThird Party Advisory
http://securitytracker.com/id?1022528 Third Party AdvisoryVDB Entry
http://www.exploit-db.com/exploits/9110 Third Party AdvisoryVDB Entry
http://www.osvdb.org/55713 Broken Link
http://www.securityfocus.com/archive/1/504795/100/0/threaded Third Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/35581 Third Party AdvisoryVDB Entry
http://www.vupen.com/english/advisories/2009/1833 PatchVendor Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00597.html Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-August/msg00608.html Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00632.html Third Party Advisory
https://www.redhat.com/archives/fedora-package-announce/2009-July/msg00676.html Third Party Advisory

Track CVE-2009-2335 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-63030WordPress REST API route confusion leads to SQL injection and RCEWordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 contain a REST API batch endpoint route confusion flaw (CWE-436). Chained with the author__not_in…KEVEPSS 10%analysed9.8CVE-2016-10033PHPMailer isMail mailSend argument injection enables remote code executionPHPMailer before 5.2.18 fails to properly sanitize the Sender property in the mailSend function of the isMail transport, allowing a crafted backslash…KEVEPSS 100%analysed5.9CVE-2026-60137WordPress WP_Query author__not_in SQL injectionWordPress core fails to properly sanitise the author__not_in parameter of WP_Query in versions before 6.8.6, 6.9.5 and 7.0.2, allowing SQL injection …KEVEPSS 5.9%analysed10.0CVE-2012-2399Wordpress vulnerabilityCross-site scripting (XSS) vulnerability in swfupload.swf in SWFupload 2.2.0.1 and earlier, as used in WordPress before 3.5.2, TinyMCE Image Manager …EPSS 8.6%10.0CVE-2012-2400Wordpress vulnerabilityUnspecified vulnerability in wp-includes/js/swfobject.js in WordPress before 3.3.2 has unknown impact and attack vectors.EPSS 3.0%10.0CVE-2011-3125Wordpress vulnerabilityUnspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Various security hard…EPSS 2.4%10.0CVE-2011-3122Wordpress vulnerabilityUnspecified vulnerability in WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 has unknown impact and attack vectors related to "Media security."EPSS 2.6%10.0CVE-2009-2853Wordpress permissions and access controls vulnerabilityWordpress before 2.8.3 allows remote attackers to gain privileges via a direct request to (1) admin-footer.php, (2) edit-category-form.php, (3) edit-…EPSS 4.7%

Source: NIST National Vulnerability Database (record CVE-2009-2335), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.