Description
WordPress is prone to multiple username enumeration weaknesses because it displays different responses to requests depending on whether or not the username exists. Attackers may exploit these weaknesses to discern valid usernames, which may aid them in brute-force password cracking or other attacks. WordPress versions prior to 2.8.1 are vulnerable.
Remediation
Update to WordPress version 2.8.1 or latest
References
http://www.coresecurity.com/content/WordPress-Privileges-Unchecked
Related Vulnerabilities
Joomla! Core 4.x.x Cross-Site Scripting (4.0.0 - 4.2.4)
WordPress Plugin WP Support Plus Responsive Ticket System Multiple Vulnerabilities (4.1)
WordPress Plugin WPCB Cross-Site Scripting (2.4.8)
WordPress Plugin Contact Form DB Cross-Site Request Forgery (2.8.31)
Apache HTTP Server Out-of-bounds Write Vulnerability (CVE-2019-10081)