Vulnerability Description
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpserveur | Wps Hide Login | < 1.9.16 |
Related Weaknesses (CWE)
References
- https://github.com/whattheslime/wps-show-login
- https://plugins.trac.wordpress.org/changeset/3099109/wps-hide-loginPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/fd21c7d3-a5f1-4c3a-b6aThird Party Advisory
- https://plugins.trac.wordpress.org/changeset/3099109/wps-hide-loginPatch
- https://www.wordfence.com/threat-intel/vulnerabilities/id/fd21c7d3-a5f1-4c3a-b6aThird Party Advisory
FAQ
What is CVE-2024-2473?
CVE-2024-2473 is a vulnerability with a CVSS score of 5.3 (MEDIUM). The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parame...
How severe is CVE-2024-2473?
CVE-2024-2473 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-2473?
Check the references section above for vendor advisories and patch information. Affected products include: Wpserveur Wps Hide Login.