AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2008-4106

MEDIUM · CVSS 5.1 EPSS 5.48% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2008-09-18 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
External Security References

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2008-4106
Severity
MEDIUM
CVSS
5.1
EPSS
5.48%
WordPress

Original NVD Description

WordPress before 2.6.2 does not properly handle MySQL warnings about insertion of username strings that exceed the maximum column width of the user_login column, and does not properly handle space characters when comparing usernames, which allows remote attackers to change an arbitrary user's password to a random value by registering a similar username and then requesting a password reset, related to a "SQL column truncation vulnerability." NOTE: the attacker can discover the random password by also exploiting CVE-2008-4107.