Hide login page <= 1.1.7 - Login Page Disclosure
Strategic Overview
<= 1.1.7CVE-2023-48335Vulnerability Overview
The Hide login page plugin for WordPress is vulnerable to protection mechanism bypass in all versions up to, and including, 1.1.7. This is due to the plugin disclosing the login path on multi-site instances. This makes it possible for unauthenticated attackers to discover the login page path and bypass the intended functionality of the security mechanism.
Technical Analysis
REMEDIATION: No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement. --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C