CVE-2023-3604: Change WP Admin < 1.1.4 - Secret Login Page Disclosure
Published Aug 21, 2023
·Updated
The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.
Affected Software
2 affected components
Wpexpertsio Change Wp Admin Login Wordpress<1.1.4
Wpexperts All In One Login Wordpress<1.1.4
Event History
Aug 21, 2023
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
DescriptionWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-3604?
CVE-2023-3604 has a medium severity rating due to its potential to disclose sensitive URL information.
2
How do I fix CVE-2023-3604?
To fix CVE-2023-3604, update the Change WP Admin Login plugin to version 1.1.4 or later.
3
What causes CVE-2023-3604 vulnerability?
CVE-2023-3604 is caused by the plugin's failure to adequately protect the hidden login page URL when accessing crafted URLs.
4
Who is affected by CVE-2023-3604?
Anyone using the Change WP Admin Login WordPress plugin versions prior to 1.1.4 is affected by CVE-2023-3604.
5
Is there an exploit available for CVE-2023-3604?
Yes, CVE-2023-3604 can be exploited by accessing specially crafted URLs that reveal the hidden login page URL.