Protect WP Admin <= 3.8 - Unauthenticated Information Disclosure to Protection Bypass
2023-06-12 00:00
Daniel RufStrategic Overview
StatusPatched in 4.0
Affected PluginProtect WP Admin
Affected Version
<= 3.8CVSS5.3Medium
CVE
CVE-2023-3139Vulnerability Overview
The Protect WP Admin plugin for WordPress is vulnerable to information disclosure in versions up to, and including, 3.8. This is due to a data leak when performing a redirect after processing a crafted request. This makes it possible for unauthenticated attackers to disclose the URL of the admin panel and bypass intended protections.
Technical Analysis
REMEDIATION: Update to version 4.0, or a newer patched version --- IDENTIFIER: CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C