The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.
The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.
The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.
The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.