{"error":0,"message":null,"data":{"name":"WPS Hide Login","plugin":"wps-hide-login","link":"https:\/\/wordpress.org\/plugins\/wps-hide-login\/","latest":"1786609920","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"9c04935a992f32e11a40aee5e9fe2dffe9554dc8dac15645b9b7b2fb38d2aa3a","name":"WPS Hide Login [wps-hide-login] < 1.9.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24917","name":"CVE-2021-24917","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24917","description":"[en] The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to \/wp-admin\/options.php as an unauthenticated user.","date":"2021-12-06"},{"id":"85d7f5841e84ccdeab1510ec931bbb959925ea32","name":"WordPress WPS Hide Login plugin <= 1.9 - Protection Bypass with Referer-Header vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wps-hide-login\/vulnerability\/wordpress-wps-hide-login-plugin-1-9-protection-bypass-with-referer-header-vulnerability","description":"Protection Bypass with Referer-Header vulnerability discovered by Daniel Ruf in WordPress WPS Hide Login plugin (versions <= 1.9).","date":"2021-10-27"},{"id":"1e678083fa794d7e4203661a2f84fb59ce0a8d20","name":"WPS Hide Login <= 1.9.0 - Hidden Login Page Location Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-190-hidden-login-page-location-disclosure","description":"The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to \/wp-admin\/options.php as an unauthenticated user.","date":"2021-10-27"},{"id":"15bb711a-7d70-4891-b7a2-c473e3e8b375","name":"WPS Hide Login &lt; 1.9.1 - Protection Bypass with Referer-Header","link":"https:\/\/wpscan.com\/vulnerability\/15bb711a-7d70-4891-b7a2-c473e3e8b375","description":"The plugin has a bug which allows to get the secret login page by setting a random referer string and making a request to \/wp-admin\/options.php as an unauthenticated user.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"n","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}]}},{"uuid":"f6868cb7e4089ae7dd31b8025790d01cbc3d94f3854366407b28894a507143cd","name":"WPS Hide Login [wps-hide-login] < 1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2015-9498","name":"CVE-2015-9498","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2015-9498","description":"[en] The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.","date":"2019-10-22"},{"id":"4d28f957a30d4e92d7af444334812333c2736667","name":"WPS Hide Login <= 1.0 - Cross-Site Request Forgery","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-10-cross-site-request-forgery","description":"The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.","date":"2015-04-27"},{"id":"ab4de351-619e-45e9-a821-e65960f3c8f6","name":"WPS Hide Login 1.0 - CSRF","link":"https:\/\/wpscan.com\/vulnerability\/ab4de351-619e-45e9-a821-e65960f3c8f6","description":"CSRF security issue when saving option value in single site and multisite mode.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}]}},{"uuid":"bd8d4d6bef8fbeb805613455cf98df9ce3d48cbeb376c33ca5feb7f4dc73ecc4","name":"WPS Hide Login [wps-hide-login] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15823","name":"CVE-2019-15823","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15823","description":"[en] The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.","date":"2019-08-30"},{"id":"2d32aa604244fc4c4a828ff028cfd243093a41dc","name":"WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'action=confirmaction'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-1522-login-page-disclosure-via-actionconfirmaction","description":"The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'action=confirmaction' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.","date":"2019-07-23"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"}}},{"uuid":"9a9cf425aa302175bc8a735c98d80ae80b0b041ac26ef7b706867390d9a615ab","name":"WPS Hide Login [wps-hide-login] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15824","name":"CVE-2019-15824","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15824","description":"[en] The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.","date":"2019-08-30"},{"id":"4fe83a34e54fd906f935ba09d8dbfeee841b4b39","name":"WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'adminhash'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-1522-login-page-disclosure-via-adminhash","description":"The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'adminhash' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.","date":"2019-07-22"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"}}},{"uuid":"99d469378e5fe83fc3358c5a0ab51eaaab309677d0c71d48fb0afc46041d9dc4","name":"WPS Hide Login [wps-hide-login] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15825","name":"CVE-2019-15825","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15825","description":"[en] The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.","date":"2019-08-30"},{"id":"2204c35bf61f3acb1967afeb2993a0dbf65e57ea","name":"WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via 'action=rp'","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-1522-login-page-disclosure-via-actionrp","description":"The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'action=rp&key&login' parameters are supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.","date":"2019-07-23"}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"}}},{"uuid":"6bf2a843173524197a051d662b034a89385b1ba78cbff5bd0c66b05ae5b970e9","name":"WPS Hide Login [wps-hide-login] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2019-15826","name":"CVE-2019-15826","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2019-15826","description":"[en] The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.","date":"2019-08-30"},{"id":"974b8704d6ecb170095dd468d63858a93567cdcc","name":"WPS Hide Login <= 1.5.2.2 - Login Page Disclosure via Referer Header","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-1522-login-page-disclosure-via-referer-header","description":"The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.\r\n\r\nThe WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when wp-login.php?action=postpass is supplied via the 'Referer' header. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.","date":"2019-07-23"},{"id":"8aecc4f1-612f-4cda-92fb-5e997504c9de","name":"WPS Hide Login &lt;= 1.5.2.2 - Multiples Issues","link":"https:\/\/wpscan.com\/vulnerability\/8aecc4f1-612f-4cda-92fb-5e997504c9de","description":"Protection Bypasses","date":null}],"impact":{"cvss":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"9.8","severity":"c","exploitable":"3.9","impact":"5.9"},"cvss3":{"version":"3.0","vector":"CVSS:3.0\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"9.8","severity":"critical","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"3.9","impact":"5.9"}}},{"uuid":"6bfc63e951b45dd836c2b2a0c41945e52490f657e13f721bc476b23264cfc51d","name":"WPS Hide Login [wps-hide-login] < 1.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-3332","name":"CVE-2021-3332","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-3332","description":"[en] WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.","date":"2021-03-01"},{"id":"236c89e16caaedd324d6358b2b12fd24b24199ee","name":"WordPress WPS Hide Login plugin <= 1.6.1 - Login Page Protection Bypass vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wps-hide-login\/vulnerability\/wordpress-wps-hide-login-plugin-1-6-1-login-page-protection-bypass-vulnerability","description":"Login Page Protection Bypass vulnerability discovered by Sebastian Schmitt in WordPress WPS Hide Login plugin (versions <= 1.6.1).","date":"2021-02-05"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}]}},{"uuid":"02d7ada7dc5bef6b07b18bf9987f97d925762f07d3174a40915c28d90eae9000","name":"WPS Hide Login [wps-hide-login] < 1.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"168885a04d04fbe904674e18b586256c1a3b3c48","name":"WordPress WPS Hide Login plugin <= 1.5.4.2 - Secret login page location disclosure vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wps-hide-login\/vulnerability\/wordpress-wps-hide-login-plugin-1-5-4-2-secret-login-page-location-disclosure-vulnerability","description":"Secret login page location disclosure vulnerability found by Jerome Bruandet in WordPress WPS Hide Login plugin (versions <= 1.5.4.2).","date":"2020-01-27"}],"impact":[]},{"uuid":"61e037c20bf2a054d7f084cdf5c9b3a17eb2d22dc867609fb00f8ea7d6fbbded","name":"WPS Hide Login [wps-hide-login] < 1.5.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"5ed74f78574a0566fe1ec88455c50385b8b49974","name":"WordPress WPS Hide Login plugin <= 1.5.2.2 - Multiples Security Issues","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wps-hide-login\/vulnerability\/wordpress-wps-hide-login-plugin-1-5-2-2-multiples-security-issues","description":"Multiples Security Issues found by Julio Potier in WordPress WPS Hide Login plugin (versions <= 1.5.2.2).","date":"2019-07-24"}],"impact":[]},{"uuid":"d58178d8602cba697f57ed9daa14df49ea097154521e2e9a20c1d5ff44203f94","name":"WPS Hide Login [wps-hide-login] < 1.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"4ec814160c4916860c1424ae065c22db0a69a367","name":"WordPress WPS Hide Login Plugin <= 1.0 - CSRF","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wps-hide-login\/vulnerability\/wordpress-wps-hide-login-plugin-1-0-csrf","description":"This plugin is prone to a cross site request forgery vulnerability.\nUpdate the plugin.","date":"2015-04-27"}],"impact":[]},{"uuid":"b8f10583fff85c3dac44378f7906738077e9011d7cff6c94a3c66362ecd878c1","name":"WPS Hide Login [wps-hide-login] < 1.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"27b71205a22e1507d20c83e4e13c08d4aa83aae8","name":"WPS Hide Login <= 1.5.4.2 - Hidden Login Page Location Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-1542-hidden-login-page-location-disclosure","description":"The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.","date":"2020-01-27"},{"id":"CVE-2020-36710","name":"CVE-2020-36710","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2020-36710","description":"[en] The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.","date":"2023-06-07"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f9ad7359b9555ebddc7e583825c0aa964f27ba8504e5c277aa57a01dca73fa88","name":"WPS Hide Login [wps-hide-login] < 1.5.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"2f0c093c-38cc-450d-bac4-0f026c7a9a0f","name":"WPS Hide Login &lt; 1.5.5 - Secret Login Page Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/2f0c093c-38cc-450d-bac4-0f026c7a9a0f","description":"fixed a vulnerability in version 1.5.4.2 and below that could allow an attacker to find and access the secret login page.","date":null}],"impact":[]},{"uuid":"aeb96255ec84a19ae636a1285312879e3ddc5f0750b1d4c25d4235848eb66eef","name":"WPS Hide Login [wps-hide-login] < 1.9.12","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.12","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-49748","name":"CVE-2023-49748","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-49748","description":"[en] Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPServeur, NicolasKulka, wpformation WPS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPS Hide Login: from n\/a through 1.9.11.","date":"2024-06-04"},{"id":"7a73f699ae03e5c88b985628876d0c93e88be709","name":"WordPress  WPS Hide Login Plugin  <= 1.9.11 is vulnerable to Bypass Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wps-hide-login\/vulnerability\/wordpress-wps-hide-login-plugin-1-9-11-secret-login-page-location-disclosure-on-multisites-vulnerability","description":"No patched version is available. No reply from the vendor.\nNaveen Muthusamy discovered and reported this Bypass Vulnerability vulnerability in WordPress WPS Hide Login Plugin. A bypass vulnerability could allow a malicious actor to bypass certain restrictions in the code. This vulnerability has not been known to be fixed yet.\nHave additional information or questions about this entry? Get in touch.","date":"2024-01-10"},{"id":"600957173cc323d467258fbd60c8c9271b33886b","name":"WPS Hide Login <= 1.9.11 - Hidden Login Page Location Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-1911-hidden-login-page-location-disclosure","description":"The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in all versions up to, and including, 1.9.11. This makes it possible for unauthenticated attackers to bypass an intended security restriction designed to prevent brute force authentication attempts on multi-site installations.","date":"2024-01-10"},{"id":"c49f1098-86e8-4570-9c44-0ccf0c25217a","name":"WPS Hide Login &lt; 1.9.12 - Hidden Login Page Location Disclosure","link":"https:\/\/wpscan.com\/vulnerability\/c49f1098-86e8-4570-9c44-0ccf0c25217a","description":"The plugin is vulnerable to login page disclosure in all versions up to, and including, 1.9.11. This makes it possible for unauthenticated attackers to bypass an intended security restriction designed to prevent brute force authentication attempts on multi-site installations.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"3.7","severity":"l","exploitable":"2.2","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"3.7","severity":"low","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.2","impact":"1.4"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f65e95f1ea0db00820470e887ac58c3e3365c67976f9d34da8ae650b710b41a0","name":"WPS Hide Login [wps-hide-login] < 1.9.16","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.16","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2473","name":"CVE-2024-2473","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2473","description":"[en] The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.","date":"2024-06-11"},{"id":"8916cc314d90813a91cb8c7a54e36dc7a78241b6","name":"WPS Hide Login <= 1.9.15.2 - Login Page Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-19152-login-page-disclosure","description":"The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.","date":"2024-06-10"},{"id":"643e732ad4b7068ef0532f87f0dc91f38b506ab5","name":"WordPress WPS Hide Login Plugin <= 1.9.15.2 is vulnerable to Bypass Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wps-hide-login\/vulnerability\/wordpress-wps-hide-login-plugin-1-9-15-2-login-page-disclosure-vulnerability","description":"<p>WordPress WPS Hide Login Plugin <= 1.9.15.2 is vulnerable to Bypass Vulnerability<\/p><p>Software: WPS Hide Login<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wps-hide-login\/#developers<\/p><p>Affected Version <= 1.9.15.2<\/p><p>Fixed in version 1.9.16 <\/p>","date":"2024-06-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-863","name":"Incorrect Authorization","description":"The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4fb6ca82d37211de4902e1cfa5ef6e74376264ce23ec0147067a2922bf4bc5b0","name":"WPS Hide Login [wps-hide-login] < 1.9.16.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.9.16.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-6289","name":"CVE-2024-6289","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-6289","description":"[en] The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.","date":"2024-07-15"},{"id":"0902e3693cd21a04a85c98ecc48360d9e076cc07","name":"WordPress WPS Hide Login Plugin < 1.9.16.4 is vulnerable to Bypass Vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/wps-hide-login\/vulnerability\/wordpress-wps-hide-login-plugin-1-9-16-4-hidden-login-page-disclosure-vulnerability","description":"<p>WordPress WPS Hide Login Plugin < 1.9.16.4 is vulnerable to Bypass Vulnerability<\/p><p>Software: WPS Hide Login<\/p><p>Link: https:\/\/wordpress.org\/plugins\/wps-hide-login\/#developers<\/p><p>Affected Version < 1.9.16.4<\/p><p>Fixed in version 1.9.16.4 <\/p>","date":"2024-07-15"},{"id":"c4c844a865c5c70004fcd4b7e044189aa0a95449","name":"WPS Hide Login <= 1.9.16.3 - Login Page Disclosure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wps-hide-login\/wps-hide-login-19163-login-page-disclosure","description":"The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.16.3. This is due to the plugin not prevent redirects to the login page when gravity forms is installed. This makes it possible for unauthenticated attackers to find the login page when it has been hidden.","date":"2024-06-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."},{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1776153795"}