Extension WordPress
Vulnérabilités WPS Hide Login
Cette page rassemble les failles publiées pour WPS Hide Login, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de WPS Hide Login
10 fiches
WPS Hide Login <= 1.9.16.3 – Login Page Disclosure
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.16.3. This is due to the plugin not prevent redirects to the login page when gravity forms is…
*-1.9.16.3
1.9.16.4
24/06/2024
WPS Hide Login <= 1.9.15.2 – Login Page Disclosure
The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes…
*-1.9.15.2
1.9.16
10/06/2024
WPS Hide Login <= 1.9.11 – Hidden Login Page Location Disclosure
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in all versions up to, and including, 1.9.11. This makes it possible for unauthenticated attackers to bypass an intended security restriction designed to prevent brute…
*-1.9.11
1.9.12
10/01/2024
WPS Hide Login <= 1.9.0 – Hidden Login Page Location Disclosure
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
*-1.9.0
1.9.1
27/10/2021
WPS Hide Login <= 1.5.4.2 – Hidden Login Page Location Disclosure
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on…
*-1.5.4.2
1.5.5
27/01/2020
WPS Hide Login <= 1.5.2.2 – Login Page Disclosure via 'action=confirmaction'
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'action=confirmaction' parameter is supplied. This makes it…
[*, 1.5.3)
1.5.3
23/07/2019
WPS Hide Login <= 1.5.2.2 – Login Page Disclosure via Referer Header
The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field. The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This…
*-1.5.2.2
1.5.3
23/07/2019
WPS Hide Login <= 1.5.2.2 – Login Page Disclosure via 'action=rp'
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'action=rp&key&login' parameters are supplied. This makes it…
*-1.5.2.2
1.5.3
23/07/2019
WPS Hide Login <= 1.5.2.2 – Login Page Disclosure via 'adminhash'
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure in versions up to, and including, 1.5.2.2. This is due to a bypass that is created when the 'adminhash' parameter is supplied. This makes it…
*-1.5.2.2
1.5.3
22/07/2019
WPS Hide Login <= 1.0 – Cross-Site Request Forgery
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.
[*, 1.1)
1.1
27/04/2015
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.