Vulnerability Description
The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Wpserveur | Wps Hide Login | < 1.9.16.4 |
Related Weaknesses (CWE)
References
- https://wpscan.com/vulnerability/fd6d0362-df1d-4416-b8b5-6e5d0ce84793/ExploitThird Party Advisory
- https://wpscan.com/vulnerability/fd6d0362-df1d-4416-b8b5-6e5d0ce84793/ExploitThird Party Advisory
FAQ
What is CVE-2024-6289?
CVE-2024-6289 is a vulnerability with a CVSS score of 6.1 (MEDIUM). The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden logi...
How severe is CVE-2024-6289?
CVE-2024-6289 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-6289?
Check the references section above for vendor advisories and patch information. Affected products include: Wpserveur Wps Hide Login.