Record summary

CVE-2023-3139 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.

Description

The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jun 22, 2023 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 22, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Protect WP Admin

Default status: unaffected

CVE ListBefore 4.0affected
VulnCheckVersion data not supplied

Nuclei templates

1
ProjectDiscoveryMEDIUMProtect WP Admin < 4.0 - Unauthenticated Protection BypassCVSS 6.1

The Protect WP Admin WordPress plugin before version 4.0 disclosed the URL of the admin panel through the redirection of a crafted URL, bypassing the protection offered.

Impact

Unauthenticated attackers can exploit URL redirection to discover the protected admin panel URL and bypass the protection mechanism offered by the plugin.

Remediation

Fixed in 4.0 or later

WeaknessesCWE-601
Authorspopcorn94
Template tagscvecve2023wordpresswp-pluginprotect-wp-adminunauthwpscanvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CPE: cpe:2.3:a:wp-experts:protect_wp_admin:*:*:*:*:*:wordpress:*:*
Shodan: http.html:"/wp-content/plugins/protect-wp-admin"
FOFA: body="/wp-content/plugins/protect-wp-admin/"

Source: ProjectDiscovery

References

3