Description
WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.
Remediation
References
Related Vulnerabilities
WordPress Plugin MStore API-Create Native Android & iOS Apps On The Cloud Security Bypass (4.10.7)
WordPress Plugin WP SEO Redirect 301 Cross-Site Request Forgery (2.3.1)
WordPress 4.5.x Multiple Vulnerabilities (4.5 - 4.5.8)
XWiki URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2023-29204)
Plone CMS Cross-Site Request Forgery (CSRF) Vulnerability (CVE-2012-5500)