WordPress Multiple Existing/Non-Existing Username Enumeration Weaknesses

WordPress is prone to multiple username-enumeration weaknesses because it displays different responses to requests depending on whether or not the username exists.

Attackers may exploit these weaknesses to discern valid usernames., which may aid them in brute-force password cracking or other attacks.

The following are vulnerable:

WordPress 2.8 and prior
WordPress MU 2.7.1 and prior


 

Privacy Statement
Copyright 2010, SecurityFocus