CVE Database /
CVE-2015-9498
CVE · High
CVE-2015-9498 — WPS Hide Login [wps-hide-login] < 1.1
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2015-9498
|
WPS Hide Login [wps-hide-login] < 1.1 |
Cross-Site Request Forgery (CSRF) |
High
8.8
|
< 1.1
|
1.1 |
2015-04-27 |
—
|
CVE-2015-9498
The wps-hide-login plugin in versions before 1.1 contains a cross-site request forgery vulnerability that allows attackers to modify option values without proper verification. An attacker could exploit this flaw by tricking an authenticated user into performing unintended actions on their WordPress site. The vulnerability was resolved in version 1.1 and later.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings