CVE-2020-36710: WPS Hide Login <= 1.5.4.2 - Hidden Login Page Location Disclosure
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36710?
CVE-2020-36710 is classified as a medium severity vulnerability due to the potential for credential brute forcing.
How do I fix CVE-2020-36710?
To fix CVE-2020-36710, update the WPS Hide Login plugin to version 1.5.4.3 or later.
Who is affected by CVE-2020-36710?
CVE-2020-36710 affects WordPress sites using the WPS Hide Login plugin versions up to and including 1.5.4.2.
What type of vulnerability is CVE-2020-36710?
CVE-2020-36710 is a login page disclosure vulnerability that allows unauthenticated attackers to access the login page.
What impact does CVE-2020-36710 have on websites?
CVE-2020-36710 allows attackers to brute force login credentials, potentially leading to unauthorized access.