CVE-2019-15823, CVE-2019-15824, CVE-2019-15825, CVE-2019-15826
The WPS Hide Login plugin for WordPress before version 1.5.3 contains a vulnerability that allows attackers to bypass the login page hiding functionality. When the parameter action=confirmaction is used, the plugin fails to properly conceal the login page, making it possible for unauthorized users to locate and access the hidden login URL.
Based on public CVE data (MITRE/NVD).