CVE-2019-15823: Critical severity wps hide login vulnerability
Published Aug 30, 2019
·Updated
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.
Affected Software
1 affected component
Wpserveur Wps Hide Login Wordpress<1.5.3
Event History
Aug 30, 2019
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15823?
CVE-2019-15823 is classified as a medium-severity vulnerability due to its potential for action confirmation bypass.
2
How do I fix CVE-2019-15823?
To fix CVE-2019-15823, update the WPS Hide Login plugin to version 1.5.3 or later.
3
Who is affected by CVE-2019-15823?
WordPress users running the WPS Hide Login plugin version before 1.5.3 are affected by CVE-2019-15823.
4
What type of vulnerability is CVE-2019-15823?
CVE-2019-15823 is a protection bypass vulnerability that allows for unauthorized actions without proper confirmation.
5
Is there a workaround for CVE-2019-15823?
The best approach is to update to the latest version of the WPS Hide Login plugin, as there are no effective workarounds for this vulnerability.