CVE-2026-84168: Easy Hide Login < 1.7 - Login Page Protection Bypass / Hidden URL Disclosure
The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover the site's configured secret login slug from the returned page, defeating the Easy Hide Login WordPress plugin before 1.7's core protection.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Easy Hide Loginto a version that resolves this vulnerability.Fixed in 1.7
Event History
Frequently Asked Questions
Who is exposed to this issue?
WordPress sites using Easy Hide Login versions earlier than 1.7 are affected. Exploitation does not require authentication.
What does an attacker need to exploit it?
An attacker needs to send password-reset requests using certain parameters. The affected protection can then allow access to the standard login page and disclose the configured secret login slug in the response.
What is the security impact of disclosing the hidden login slug?
The plugin’s hidden-login protection is defeated because an attacker can recover the secret URL configured to hide the login page. This exposes the protected login entry point to unauthenticated users.