WPS Hide Login <= 1.9.16.3 - Login Page Disclosure
medium
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.16.3. This is due to the plugin not prevent redirects to the login page when gravity forms is installed. This makes it possible for unauthenticated attackers to find the login page when it has been h...
- CVSS:
- 5.3
- Affected:
- up to 1.9.16.3
- Fixed in:
- 1.9.16.4
- Disclosed:
- Jun 24, 2024
CVE-2024-6289 on NVD →
WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
medium
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the...
- CVSS:
- 5.3
- Affected:
- up to 1.9.15.2
- Fixed in:
- 1.9.16
- Disclosed:
- Jun 10, 2024
CVE-2024-2473 on NVD →
WPS Hide Login <= 1.9.11 - Hidden Login Page Location Disclosure
low
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in all versions up to, and including, 1.9.11. This makes it possible for unauthenticated attackers to bypass an intended security restriction designed to prevent brute force authentication attempts on multi-site installations.
- CVSS:
- 3.7
- Affected:
- up to 1.9.11
- Fixed in:
- 1.9.12
- Disclosed:
- Jan 10, 2024
CVE-2023-49748 on NVD →
WPS Hide Login <= 1.9.0 - Hidden Login Page Location Disclosure
medium
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
- CVSS:
- 5.3
- Affected:
- up to 1.9.0
- Fixed in:
- 1.9.1
- Disclosed:
- Oct 27, 2021
CVE-2021-24917 on NVD →
WPS Hide Login <= 1.5.4.2 - Hidden Login Page Location Disclosure
medium
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
- CVSS:
- 5.3
- Affected:
- up to 1.5.4.2
- Fixed in:
- 1.5.5
- Disclosed:
- Jan 27, 2020
CVE-2020-36710 on NVD →
WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'action=rp'
medium
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'action=rp&key&login' parameters are supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by th...
- CVSS:
- 5.3
- Affected:
- up to 1.5.2.2
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 23, 2019
CVE-2019-15825 on NVD →
WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via Referer Header
medium
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when wp-login.php?action=postpass is su...
- CVSS:
- 5.3
- Affected:
- up to 1.5.2.2
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 23, 2019
CVE-2019-15826 on NVD →
WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'action=confirmaction'
medium
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'action=confirmaction' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the...
- CVSS:
- 5.3
- Affected:
- up to 1.5.3
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 23, 2019
CVE-2019-15823 on NVD →
WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'adminhash'
medium
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'adminhash' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.
- CVSS:
- 5.3
- Affected:
- up to 1.5.2.2
- Fixed in:
- 1.5.3
- Disclosed:
- Jul 22, 2019
CVE-2019-15824 on NVD →
WPS Hide Login <= 1.0 - Cross-Site Request Forgery
high
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
- CVSS:
- 8.8
- Affected:
- up to 1.1
- Fixed in:
- 1.1
- Disclosed:
- Apr 27, 2015
CVE-2015-9498 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database