Admin login URL Change

Admin login URL Change has one disclosed vulnerability in the WordSec catalog, all reported in 2026; it is fixed as of September 2026. Their average CVSS score is 4.3, and the most serious one scores 4.3 out of 10.

The most common weakness is Missing Authorization, behind 1 of the records (100%).

The one issue recorded for Admin login URL Change has a vendor fix available, so running the current release closes it.

All of these findings were reported by Mohamad Fattyr. Admin login URL Change is installed on roughly 2,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.1.

Strategic Overview

Avg CVSSMedium
4.3/ 10
Patch Coverage100%
Open

0

Fixed

1

Get automatic notifications for all Admin login URL Change vulnerabilities before they are exploited.

Highest severity on recordCVSS 4.3CVE-2026-24578

Admin login URL Change <= 1.1.5 - Missing Authorization

Read the full analysis

Vulnerability Records

1 records
Admin login URL Change banner
Latestv1.2.2

Admin login URL Change

Jahid Hasan

Author

Jahid Hasan

5.0(4)
100/100
Last Updated
2026-08-26 (18d ago)
Active Installs
2,000+
Downloads
22,715
Requires WP
4.7+
Requires PHP
5.3+
Tested up to
WP 7.1
Created
2021-11-23 (5y ago)

Admin login URL Change is a very lightweight, highly secure plugin that lets you easily and safely change the URL of the login form page to anything you want. It does not change any core files. It simply intercepts page requests and works on any WordPress website. This is great for your convenience, but it also closes the door to would-be brute-force attackers. Why Use Admin Login URL Change? WordPress websites are common targets for automated bots and hackers attempting to gain unauthorized access via brute-force login attempts. The default login URLs (wp-login.php and wp-admin) are widely known, making them easy targets. Admin Login URL Change solves this problem by letting you rename your login URL to something unique, effectively closing this security loophole. 🚀 Get Even More Security with Pro Features! Upgrade to the Pro Version to unlock elite-level protection mechanisms: * IP Address Blocker: Block individual IPs or entire CIDR ranges from even accessing your custom login page, featuring auto-ban thresholds, ban durations, and email alerts. * Searchable Country Blocker: Restrict login access to specific countries using a live, search-filtered database of 200+ global regions. * Login Attempt Limiter: Set max retries, retry windows, lockout durations, and display warning alerts to prevent dictionary and brute-force attacks. * Two-Factor Authentication (2FA): Add an ironclad second layer of verification via Authenticator Apps (Google Authenticator, Authy, Microsoft Authenticator) or Email OTP. * Login Alerts: Receive instant email notifications whenever someone successfully logs in or fails to log in — with IP, username, and timestamp included. * Full Login Audit Log: Unlimited login history (up to 500 entries) with user-agent details, replacing the free 10-entry limit. How to use the plugin Go to your dashboard and navigate to the Admin Login Slug menu. Enter your custom login slug (e.g. madmin). Click “Save Settings”. Bookmark your new URL and test it!

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C