CVE-2019-15823, CVE-2019-15824, CVE-2019-15825, CVE-2019-15826
The WPS Hide Login plugin for WordPress through version 1.5.2.2 contains a flaw that allows attackers to bypass the login page hiding functionality when the 'action=confirmaction' parameter is included in requests. This vulnerability enables threat actors to discover hidden login pages that administrators intended to conceal using the plugin. The issue was resolved in version 1.5.3 or later.
Based on public CVE data (MITRE/NVD).