CVE-2023-47818: WordPress LWS Hide Login plugin <= 2.1.8 - Secret Login Page Location Disclosure on Multisites vulnerability
Published Jun 4, 2024
·Updated
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in LWS LWS Hide Login allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects LWS Hide Login: from n/a through 2.1.8.
Affected Software
2 affected components
LWS Hide Login<=2.1.8
WordPress LWS Hide Login<=2.1.8
Remediation
Information
Update to 2.1.9 or a higher version.
Event History
Jun 4, 2024
CVE Published
via MITRE·10:08 AM
Data Sourced
via MITRE·10:08 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-47818?
CVE-2023-47818 is classified as a medium severity vulnerability.
2
How do I fix CVE-2023-47818?
To fix CVE-2023-47818, update the LWS Hide Login plugin to the latest version above 2.1.8.
3
What type of vulnerability is CVE-2023-47818?
CVE-2023-47818 is an exposure of sensitive information to an unauthorized actor vulnerability.
4
Which software is affected by CVE-2023-47818?
CVE-2023-47818 affects LWS Hide Login versions up to and including 2.1.8.
5
What are the potential risks associated with CVE-2023-47818?
The risks associated with CVE-2023-47818 include unauthorized access to functionality due to improper ACL constraints.