CVE · Critical

CVE-2019-15823 — WPS Hide Login [wps-hide-login] < 1.5.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-15823, CVE-2019-15824, CVE-2019-15825, CVE-2019-15826 WPS Hide Login [wps-hide-login] < 1.5.3 Critical 9.8 < 1.5.3 1.5.3 2019-07-23

CVE-2019-15823, CVE-2019-15824, CVE-2019-15825, CVE-2019-15826

The WPS Hide Login plugin for WordPress before version 1.5.3 contains a vulnerability that allows attackers to bypass the login page hiding functionality. When the parameter action=confirmaction is used, the plugin fails to properly conceal the login page, making it possible for unauthorized users to locate and access the hidden login URL.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.