LWS Hide Login

LWS Hide Login has 3 disclosed vulnerabilities in the WordSec catalog, reported between 2022 and 2023; all 3 are fixed as of September 2026. Their average CVSS score is 6.1, and the most serious one scores 8.8 out of 10. Severity breakdown: 0 critical and 1 high. 2023 was the busiest year with 2 disclosures.

The most common weakness is Cross-Site Request Forgery (CSRF), behind 1 of the records (33%). Other recurring categories include Missing Authorization, Protection Mechanism Failure.

Every one of the 3 issues recorded for LWS Hide Login has a vendor fix available, so running the current release closes all known holes.

2 independent researchers contributed these findings, one record each. LWS Hide Login is installed on roughly 20,000 WordPress sites, so each unpatched flaw has a wide blast radius. The current release is tested up to WordPress 7.0.4.

Strategic Overview

Avg CVSSMedium
6.1/ 10
Patch Coverage100%
Open

0

Fixed

3

Get automatic notifications for all LWS Hide Login vulnerabilities before they are exploited.

Highest severity on recordCVSS 8.8

LWS Plugins <= (Various Versions) - Missing Authorization Checks

Read the full analysis

Vulnerability Records

3 records
LWS Hide Login banner
Latestv2.2.5

LWS Hide Login

Aurélien LWS

Author

Aurélien LWS

4.7(12)
94/100
Last Updated
2026-06-15 (3mo ago)
Active Installs
20,000+
Downloads
212,344
Requires WP
5.0+
Requires PHP
7.0+
Tested up to
WP 7.0.4
Created
2022-08-29 (4y ago)

Secure your website with this plugin ! Redirect your users if they try to access your admin page directly. Choose your own link from your login page and protect your website. Dashboard redirection By default, the 404 page is displayed when trying to access the administration or login page without being logged in or with the wrong URL. You can change this redirection to any page you like. New login address By default, the login page to access your wordpress dashboard is accessible at the address of your domain to which we add the suffix /wp-admin or /wp-login.php. By changing the login address via the LWS Hide Login plugin, the wp-admin directory and the wp-login.php page become inaccessible, you will have to use the new URL to login. If you deactivate this plugin, your site will be as it was before, accessible at the old URL. This plugin is pre-installed when ordering one of these LWS webhosts: WordPress hosting, Classic shared web hosting and cPanel hosting (soon) License Released under the terms of the GNU General Public License.

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C