Record summary

CVE-2019-15823 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryHIGHWPS Hide Login <= 1.5.2.2 - Login Page Bypass

WPS-Hide-Login plugin before 1.5.3 for WordPress contains an action=confirmaction protection bypass, letting attackers bypass security checks, exploit requires sending crafted requests.

Impact

Attackers can bypass login protection, potentially leading to unauthorized access.

Remediation

Update to version 1.5.3 or later.

Authorspussycat0x
Template tagscvecve2019wordpresswp-pluginwpdisclosurewps-hide-loginvuln
FOFA: body="/wp-content/plugins/wps-hide-login"

Source: ProjectDiscovery

References

4