CVE · Critical

CVE-2019-15826 — WPS Hide Login [wps-hide-login] < 1.5.3

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2019-15826 WPS Hide Login [wps-hide-login] < 1.5.3 Critical 9.8 < 1.5.3 1.5.3 2019-07-23

CVE-2019-15826

The WPS Hide Login plugin for WordPress up to version 1.5.2.2 contains a security bypass that allows attackers to discover hidden login pages. An attacker can circumvent the plugin's protection mechanism by providing wp-login.php?action=postpass through the Referer header, thereby revealing the location of the obscured login page. This vulnerability was patched in version 1.5.3.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.