Defender Security <= 4.0.2 - Hide Login Page Feature Protection Bypass
2023-09-06 00:00
Juan Pablo Gomez PostigoStrategic Overview
StatusPatched in 4.1.0
Affected Version
<= 4.0.2CVSS5.3Medium
CVE
CVE-2023-5089Vulnerability Overview
The Defender Security plugin for WordPress is vulnerable to protection bypass in versions up to, and including, 4.0.2. This is due to the plugin failing to prevent redirects via the auth_redirect WordPress function. This makes it possible for unauthenticated attackers to bypass the 'Hide Login Page' security feature.
Technical Analysis
REMEDIATION: Update to version 4.1.0, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C