CVE-2023-3139
Protect WP Admin < 4.0 - Unauthenticated Protection Bypass
Record summary
CVE-2023-3139 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Jun 22, 2023 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 22, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Protect WP AdminDefault status: unaffected | CVE List | Before 4.0 | affected |
protect_wp_adminBrowse wp-experts / protect_wp_admin | VulnCheck | Version data not supplied | |
Nuclei templates
1ProjectDiscoveryMEDIUMProtect WP Admin < 4.0 - Unauthenticated Protection BypassCVSS 6.1
The Protect WP Admin WordPress plugin before version 4.0 disclosed the URL of the admin panel through the redirection of a crafted URL, bypassing the protection offered.
Impact
Unauthenticated attackers can exploit URL redirection to discover the protected admin panel URL and bypass the protection mechanism offered by the plugin.
Remediation
Fixed in 4.0 or later
Source: ProjectDiscovery