Ultimate Dashboard <= 3.7.10 - Login Page Disclosure on Multi-site
2023-12-05 00:00
Naveen MuthusamyStrategic Overview
StatusPatched in 3.7.11
Affected PluginUltimate Dashboard – Custom WordPress Dashboard
Affected Version
<= 3.7.10CVSS5.3Medium
CVE
CVE-2023-49822Vulnerability Overview
The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to secret login page disclosure in all versions up to, and including, 3.7.10. This makes it possible for unauthenticated attackers to discover the secret login page URL on multi-site instances
Technical Analysis
REMEDIATION: Update to version 3.7.11, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C