CVE-2019-15826: Critical severity wps hide login vulnerability
Published Aug 30, 2019
·Updated
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
Affected Software
1 affected component
Wpserveur Wps Hide Login Wordpress<1.5.3
Event History
Aug 30, 2019
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-15826?
The severity of CVE-2019-15826 is rated as critical with a score of 9.8.
2
What plugin is affected by CVE-2019-15826?
The wps-hide-login plugin before version 1.5.3 for WordPress is affected by CVE-2019-15826.
3
How can the protection bypass be exploited in CVE-2019-15826?
The protection bypass in CVE-2019-15826 can be exploited via wp-login.php in the Referer field.