CVE-2024-6289
WPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
Record summary
CVE-2024-6289 has a selected CVSS score of 6.1 (medium); EIP currently links 1 Nuclei template.
Description
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 24, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
WPS Hide LoginDefault status: unaffected | CVE List | Before 1.9.16.4 | affected |
wps_hide_loginBrowse wpserveur / wps_hide_loginDefault status: unknown | CVE List | Before 1.9.16.4 | affected |
Nuclei templates
1ProjectDiscoveryMEDIUMWPS Hide Login < 1.9.16.4 - Hidden Login Page Disclosure
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
Impact
Unauthenticated attackers can discover and access the hidden WordPress login page by exploiting improper redirect handling, defeating the security-by-obscurity measure.
Remediation
Update WPS Hide Login plugin to version 1.9.16.4 or later to address the login page disclosure vulnerability.
Source: ProjectDiscovery