Ultimate Dashboard <= 3.7.10 - Login Page Disclosure on Multi-site

2023-12-05 00:00
Naveen Muthusamy

Strategic Overview

Status
Patched in 3.7.11
Affected Version<= 3.7.10
CVSS5.3Medium
CVECVE-2023-49822
View all Ultimate Dashboard – Custom WordPress Dashboard vulnerabilities

Vulnerability Overview

The Ultimate Dashboard – Custom WordPress Dashboard plugin for WordPress is vulnerable to secret login page disclosure in all versions up to, and including, 3.7.10. This makes it possible for unauthenticated attackers to discover the secret login page URL on multi-site instances

Technical Analysis

REMEDIATION: Update to version 3.7.11, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C