WordPress Core < 3.1.3 - Username Enumeration

2011-05-25 00:00
Verónica Valeros

Strategic Overview

Status
Patched in 3.1.3
Affected CoreWordPress 3.1
Affected Version<= 3.1.2
CVSS5.3Medium
CVECVE-2011-3126
View all WordPress 3.1 vulnerabilities

Vulnerability Overview

WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.

Technical Analysis

REMEDIATION: Update to version 3.1.3, or a newer patched version --- IDENTIFIER: CWE-204 (Observable Response Discrepancy) The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C