S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2021-24917 Scanner

CVE-2021-24917 scanner - Protection Bypass vulnerability in WPS Hide Login plugin for WordPress

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
3
Vulnerabilities Found
confirmed findings
References
CVECVE-2021-24917
7.5
CVSS

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
WPS Hide Login
AFFECTED< 1.9.1SAFE ✓≥ 1.9.1
Updated Aug 21, 2026View on NVD →
Detail

WPS Hide Login is a WordPress plugin that is commonly used to enhance the security of WordPress websites. Essentially, the plugin is supposed to help website owners to hide and customize their login URLs for security reasons. With the WPS Hide Login plugin, users are able to prevent brute force attacks, as well as reduce the risk of unauthorized access to their WordPress dashboard.

CVE-2021-24917 is a critical vulnerability that has been detected in the WPS Hide Login plugin before version 1.9.1. This vulnerability arises as a result of an error in the plugin's code, which makes it possible for hackers to access the secret login page through a random referer string. In simpler terms, this means that hackers can easily bypass the security measures put in place by the plugin, making it possible for them to access your website dashboard without any authorization.

When exploited, this vulnerability can lead to significant damage to your website. Some of the potential consequences of this vulnerability include data leaks, website downtime, content injection, unauthorized content modification, and the ability for hackers to take control of your website. All of these consequences can be detrimental to the success and reputation of your website and business.

At s4e.io, we provide an advanced digital asset monitoring service that helps website owners to quickly and easily identify any vulnerabilities in their websites. With our pro features, you can stay one step ahead of hackers and ensure that your website stays secure, regardless of any new vulnerabilities that may arise. Sign up today and enjoy peace of mind knowing that your website is protected.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that website owners can take. Here are some of the measures that you can consider implementing:

  • Update your WPS Hide Login plugin to the latest version (version 1.9.1 or later). This version includes a fix for the CVE-2021-24917 vulnerability.
  • Install a reliable WordPress security plugin that is designed to detect and prevent vulnerabilities on your website.
  • Make use of two-factor authentication to add an extra layer of security to your website login process.
  • Use a strong and unique password for your website administrator account.
  • Regularly update and backup your website to ensure that your data stays protected in case of a cyberattack.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.