WPS Hide Login <= 1.9.0 - Hidden Login Page Location Disclosure

2021-10-27 00:00
Daniel Ruf

Strategic Overview

Status
Patched in 1.9.1
Affected PluginWPS Hide Login
Affected Version<= 1.9.0
CVSS5.3Medium
CVECVE-2021-24917
View all WPS Hide Login vulnerabilities

Vulnerability Overview

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

Technical Analysis

REMEDIATION: Update to version 1.9.1, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C