CVE · Critical

CVE-2019-15824 — WPS Hide Login [wps-hide-login] < 1.5.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-15823, CVE-2019-15824, CVE-2019-15825, CVE-2019-15826 WPS Hide Login [wps-hide-login] < 1.5.3 Critical 9.8 < 1.5.3 1.5.3 2019-07-23

CVE-2019-15823, CVE-2019-15824, CVE-2019-15825, CVE-2019-15826

The WPS Hide Login plugin for WordPress through version 1.5.2.2 contains a flaw that allows attackers to bypass the login page hiding functionality when the 'action=confirmaction' parameter is included in requests. This vulnerability enables threat actors to discover hidden login pages that administrators intended to conceal using the plugin. The issue was resolved in version 1.5.3 or later.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.