CVE-2023-5089: Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the authredirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-5089?
CVE-2023-5089 is a vulnerability in the Defender Security WordPress plugin before version 4.1.0 that allows an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
How can an attacker exploit CVE-2023-5089?
An attacker can exploit CVE-2023-5089 by redirecting visitors to the login page via the auth_redirect WordPress function, even when the hide login page functionality is enabled.
What is the severity of CVE-2023-5089?
CVE-2023-5089 has a severity rating of medium with a CVSS score of 5.3.
What software is affected by CVE-2023-5089?
The Defender Security WordPress plugin before version 4.1.0 is affected by CVE-2023-5089.
Are there any references for CVE-2023-5089?
Yes, you can find more information about CVE-2023-5089 at the following references: [Reference 1](https://wpscan.com/vulnerability/2b547488-187b-44bc-a57d-f876a7d4c87d), [Reference 2](https://www.sprocketsecurity.com/resources/discovering-wp-admin-urls-in-wordpress-with-gravityforms)