CVE-2024-2473: WPS Hide Login <= 1.9.15.2 - Login Page Disclosure
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2473?
CVE-2024-2473 is classified as a Medium severity vulnerability due to its potential for login page disclosure.
How do I fix CVE-2024-2473?
To fix CVE-2024-2473, update the WPS Hide Login plugin to version 1.9.16 or later.
What systems are affected by CVE-2024-2473?
CVE-2024-2473 affects all versions of the WPS Hide Login plugin for WordPress up to and including 1.9.15.2.
What is the impact of CVE-2024-2473?
The impact of CVE-2024-2473 allows attackers to easily discover the login page of a WordPress site.
Is there a workaround for CVE-2024-2473?
There is no known workaround for CVE-2024-2473; the recommended action is to update the plugin.