Protection Bypass in WPS Hide Login Plugin for WordPress
CVE-2019-15826
9.8CRITICAL
What is CVE-2019-15826?
The WPS Hide Login plugin for WordPress prior to version 1.5.3 is susceptible to a protection bypass vulnerability. This issue arises from improper handling of the Referer field in the wp-login.php file, potentially allowing unauthorized access to the login page. Users are advised to update to the latest version to mitigate this risk.