WPS Hide Login <= 1.9.0 - Hidden Login Page Location Disclosure
2021-10-27 00:00
Daniel RufStrategic Overview
StatusPatched in 1.9.1
Affected PluginWPS Hide Login
Affected Version
<= 1.9.0CVSS5.3Medium
CVE
CVE-2021-24917Vulnerability Overview
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
Technical Analysis
REMEDIATION: Update to version 1.9.1, or a newer patched version --- IDENTIFIER: CWE-863 (Incorrect Authorization) The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C