CVE · Medium

CVE-2024-2473 — WPS Hide Login [wps-hide-login] < 1.9.16

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-2473 WPS Hide Login [wps-hide-login] < 1.9.16 Incorrect Authorization Medium 5.3 < 1.9.16 1.9.16 2024-06-10

CVE-2024-2473

The WPS Hide Login plugin for WordPress versions up to 1.9.15.2 contains a vulnerability that allows the login page location to be disclosed despite being hidden. An attacker can bypass the plugin's protection by supplying the 'action=postpass' parameter, which reveals the hidden login page URL. This flaw was resolved in version 1.9.16.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.