CVE-2019-15824: Critical severity wps hide login vulnerability
Published Aug 30, 2019
·Updated
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
Affected Software
1 affected component
Wpserveur Wps Hide Login Wordpress<1.5.3
Event History
Aug 30, 2019
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15824?
CVE-2019-15824 has been rated as a critical vulnerability due to its potential for adminhash protection bypass.
2
How do I fix CVE-2019-15824?
To fix CVE-2019-15824, update the WPS Hide Login plugin to version 1.5.3 or later.
3
What versions are affected by CVE-2019-15824?
CVE-2019-15824 affects all versions of the WPS Hide Login plugin prior to 1.5.3.
4
What are the implications of CVE-2019-15824?
CVE-2019-15824 allows unauthorized access to the WordPress admin area by bypassing the adminhash protection.
5
Is there a workaround for CVE-2019-15824?
The recommended workaround for CVE-2019-15824 is to disable the WPS Hide Login plugin until an update can be applied.