Protect WP Admin <= 3.8 - Unauthenticated Information Disclosure to Protection Bypass

2023-06-12 00:00
Daniel Ruf

Strategic Overview

Status
Patched in 4.0
Affected PluginProtect WP Admin
Affected Version<= 3.8
CVSS5.3Medium
CVECVE-2023-3139
View all Protect WP Admin vulnerabilities

Vulnerability Overview

The Protect WP Admin plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.8. This is due to a data leak when performing a redirect after processing a crafted request. This makes it possible for unauthenticated attackers to disclose the URL of the admin panel and bypass intended protections.

Technical Analysis

REMEDIATION: Update to version 4.0, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C