CVE-2007-0109: Medium severity WordPress vulnerability
Published Jan 9, 2007
·Updated
wp-login.php in WordPress 2.0.5 and earlier displays different error messages if a user exists or not, which allows remote attackers to obtain sensitive information and facilitates brute force attacks.
Affected Software
6 affected components
WordPress=2.0
WordPress=2.0.1
WordPress=2.0.2
WordPress=2.0.3
WordPress=2.0.4
WordPress=2.0.5
Event History
Jan 9, 2007
CVE Published
12:28 AM
Data Sourced
via NVD·12:28 AM
DescriptionSeverityAffected Software
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-0109?
CVE-2007-0109 is considered a medium-severity vulnerability due to its potential to facilitate brute force attacks.
2
How do I fix CVE-2007-0109?
To fix CVE-2007-0109, upgrade to a version of WordPress later than 2.0.5.
3
What type of vulnerability is CVE-2007-0109?
CVE-2007-0109 is an information disclosure vulnerability that reveals user existence through different error messages.
4
What versions of WordPress are affected by CVE-2007-0109?
CVE-2007-0109 affects WordPress versions 2.0 through 2.0.5.
5
Can CVE-2007-0109 lead to account compromise?
Yes, CVE-2007-0109 can lead to account compromise by enabling attackers to efficiently conduct brute force authentication attacks.