Defender Security <= 4.0.2 - Hide Login Page Feature Protection Bypass

2023-09-06 00:00
Juan Pablo Gomez Postigo

Vulnerability Overview

The Defender Security plugin for WordPress is vulnerable to protection bypass in versions up to, and including, 4.0.2. This is due to the plugin failing to prevent redirects via the auth_redirect WordPress function. This makes it possible for unauthenticated attackers to bypass the 'Hide Login Page' security feature.

Technical Analysis

REMEDIATION: Update to version 4.1.0, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C