Record summary

CVE-2022-1595 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.

Description

The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

HC Custom WP-Admin URL

CVE List1.4 to ≤ 1.4affected

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress HC Custom WP-Admin URL <=1.4 - Admin Login URL DisclosureCVSS 5.3

The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request

Impact

Attackers can obtain the secret custom admin login URL by sending crafted requests with specific cookies, potentially facilitating brute force attacks against the admin panel.

Remediation

Update to the latest version of WordPress HC Custom WP-Admin URL plugin (>=1.5) to mitigate the vulnerability.

WeaknessesCWE-200
Authorstheamanrawat, oleveloper
Template tagscvecve2022unauthwpscanwordpresswp-pluginwphc-custom-wp-admin-urlvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:hc_custom_wp-admin_url_project:hc_custom_wp-admin_url:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

2