CVE-2021-24917: WPS Hide Login < 1.9.1 - Protection Bypass with Referer-Header
Published Dec 6, 2021
·Updated
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
Affected Software
1 affected component
Wpserveur Wps Hide Login Wordpress<1.9.1
Event History
Dec 6, 2021
CVE Published
via MITRE·03:55 PM
Data Sourced
via MITRE·03:55 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-24917?
CVE-2021-24917 has a medium severity rating due to its potential to expose the secret login page to unauthorized users.
2
How do I fix CVE-2021-24917?
To fix CVE-2021-24917, update the WPS Hide Login plugin to version 1.9.1 or later.
3
Which versions of the WPS Hide Login plugin are affected by CVE-2021-24917?
CVE-2021-24917 affects all versions of the WPS Hide Login plugin prior to 1.9.1.
4
What type of attack does CVE-2021-24917 facilitate?
CVE-2021-24917 facilitates unauthorized access to the secret login page through a crafted referer string.
5
Who is at risk of CVE-2021-24917?
Any WordPress site using the WPS Hide Login plugin before version 1.9.1 is at risk of CVE-2021-24917.