nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-1595 CVE-2022-1595
MEDIUMNuclei
HC Custom WP-Admin URL <= 1.4 - Unauthenticated Secret URL Disclosure
Record summary
CVE-2022-1595 has a selected CVSS score of 5.3 (medium); EIP currently links 1 Nuclei template.
Description
The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
HC Custom WP-Admin URL | CVE List | 1.4 to ≤ 1.4 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress HC Custom WP-Admin URL <=1.4 - Admin Login URL DisclosureCVSS 5.3
The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request
Impact
Attackers can obtain the secret custom admin login URL by sending crafted requests with specific cookies, potentially facilitating brute force attacks against the admin panel.
Remediation
Update to the latest version of WordPress HC Custom WP-Admin URL plugin (>=1.5) to mitigate the vulnerability.
WeaknessesCWE-200
Authorstheamanrawat, oleveloper
Template tagscvecve2022unauthwpscanwordpresswp-pluginwphc-custom-wp-admin-urlvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CPE: cpe:2.3:a:hc_custom_wp-admin_url_project:hc_custom_wp-admin_url:*:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/0218c90c-8f79-4f37-9a6f-60cf2f47d47b https://wordpress.org/plugins/hc-custom-wp-admin-url/ https://nvd.nist.gov/vuln/detail/CVE-2022-1595
Source: ProjectDiscovery
References
2wpscan.com
https://wpscan.com/vulnerability/0218c90c-8f79-4f37-9a6f-60cf2f47d47b