WordPress Core < 3.1.3 - Username Enumeration
2011-05-25 00:00
Verónica ValerosStrategic Overview
StatusPatched in 3.1.3
Affected CoreWordPress 3.1
Affected Version
<= 3.1.2CVSS5.3Medium
CVE
CVE-2011-3126Vulnerability Overview
WordPress 3.1 before 3.1.3 and 3.2 before Beta 2 allows remote attackers to determine usernames of non-authors via canonical redirects.
Technical Analysis
REMEDIATION: Update to version 3.1.3, or a newer patched version --- IDENTIFIER: CWE-204 (Observable Response Discrepancy) The product provides different responses to incoming requests in a way that reveals internal state information to an unauthorized actor outside of the intended control sphere.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C