CVE-2024-6289

Severity CVSS v4.0:
Pending analysis
Type:
CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
Publication date:
15/07/2024
Last modified:
17/03/2025

Description

The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpserveur:wps_hide_login:*:*:*:*:*:wordpress:*:* 1.9.16.4 (excluding)