First published: Mon Oct 16 2023(Updated: )
The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
Credit: contact@wpscan.com contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WPMU DEV Defender Security | <4.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-5089 is a vulnerability in the Defender Security WordPress plugin before version 4.1.0 that allows an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
An attacker can exploit CVE-2023-5089 by redirecting visitors to the login page via the auth_redirect WordPress function, even when the hide login page functionality is enabled.
CVE-2023-5089 has a severity rating of medium with a CVSS score of 5.3.
The Defender Security WordPress plugin before version 4.1.0 is affected by CVE-2023-5089.
Yes, you can find more information about CVE-2023-5089 at the following references: [Reference 1](https://wpscan.com/vulnerability/2b547488-187b-44bc-a57d-f876a7d4c87d), [Reference 2](https://www.sprocketsecurity.com/resources/discovering-wp-admin-urls-in-wordpress-with-gravityforms)