plugin

Wps Hide Login Vulnerabilities

10 known security issues reported for the Wps Hide Login WordPress plugin. Most recent disclosed Jun 24, 2024.

1 high 8 medium 1 low

Running Wps Hide Login on your site? Check whether your installed version is affected.

Scan your site free

WPS Hide Login <= 1.9.16.3 - Login Page Disclosure

medium

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.16.3. This is due to the plugin not prevent redirects to the login page when gravity forms is installed. This makes it possible for unauthenticated attackers to find the login page when it has been h...

CVSS:
5.3
Affected:
up to 1.9.16.3
Fixed in:
1.9.16.4
Disclosed:
Jun 24, 2024

CVE-2024-6289 on NVD →

WPS Hide Login <= 1.9.15.2 - Login Page Disclosure

medium

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the...

CVSS:
5.3
Affected:
up to 1.9.15.2
Fixed in:
1.9.16
Disclosed:
Jun 10, 2024

CVE-2024-2473 on NVD →

WPS Hide Login <= 1.9.11 - Hidden Login Page Location Disclosure

low

The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in all versions up to, and including, 1.9.11. This makes it possible for unauthenticated attackers to bypass an intended security restriction designed to prevent brute force authentication attempts on multi-site installations.

CVSS:
3.7
Affected:
up to 1.9.11
Fixed in:
1.9.12
Disclosed:
Jan 10, 2024

CVE-2023-49748 on NVD →

WPS Hide Login <= 1.9.0 - Hidden Login Page Location Disclosure

medium

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

CVSS:
5.3
Affected:
up to 1.9.0
Fixed in:
1.9.1
Disclosed:
Oct 27, 2021

CVE-2021-24917 on NVD →

WPS Hide Login <= 1.5.4.2 - Hidden Login Page Location Disclosure

medium

The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.

CVSS:
5.3
Affected:
up to 1.5.4.2
Fixed in:
1.5.5
Disclosed:
Jan 27, 2020

CVE-2020-36710 on NVD →

WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'action=rp'

medium

The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'action=rp&key&login' parameters are supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by th...

CVSS:
5.3
Affected:
up to 1.5.2.2
Fixed in:
1.5.3
Disclosed:
Jul 23, 2019

CVE-2019-15825 on NVD →

WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via Referer Header

medium

The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field. The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when wp-login.php?action=postpass is su...

CVSS:
5.3
Affected:
up to 1.5.2.2
Fixed in:
1.5.3
Disclosed:
Jul 23, 2019

CVE-2019-15826 on NVD →

WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'action=confirmaction'

medium

The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'action=confirmaction' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the...

CVSS:
5.3
Affected:
up to 1.5.3
Fixed in:
1.5.3
Disclosed:
Jul 23, 2019

CVE-2019-15823 on NVD →

WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'adminhash'

medium

The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'adminhash' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.

CVSS:
5.3
Affected:
up to 1.5.2.2
Fixed in:
1.5.3
Disclosed:
Jul 22, 2019

CVE-2019-15824 on NVD →

WPS Hide Login <= 1.0 - Cross-Site Request Forgery

high

The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.

CVSS:
8.8
Affected:
up to 1.1
Fixed in:
1.1
Disclosed:
Apr 27, 2015

CVE-2015-9498 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database