Showing 3 vulnerabilities on this page for wps_hide_login

Signals CISA KEV Ransomware Nuclei
wpserveur vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure

The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

CWE-203CWE-601Jul 15, 20241 related artifact
CVSS6.1v3.1EPSS0.904%PoCs0SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WPS Hide Login <= 1.9.15.2 - Login Page Disclosure

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.

CWE-863Jun 11, 20241 related artifact
CVSS5.3v3.1EPSS1.23%PoCs2SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei templateSTIX

WordPress WPS Hide Login plugin <= 1.9.11 - Secret Login Page Location Disclosure on Multisites vulnerability

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPServeur, NicolasKulka, wpformation WPS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects WPS Hide Login: from n/a through 1.9.11.

CWE-200Jun 4, 2024
CVSS3.7v3.1EPSS0.303%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX