S4E just found a critical-severity finding from cve-2022-27924 scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Sep 16, 2024

CVE-2024-6289 Scanner

CVE-2024-6289 scanner - Path Traversal vulnerability in WPS Hide Login

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
2.6k
Times Used
continuous scan runs
4.2k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-6289
6.1
CVSSmedium
Exploitable remotely over the internet · no authentication required · user interaction needed.

The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

Attack Vector
Network
Privileges Req.
None
User Interaction
Required
Affected
WPS Hide Login
AFFECTED< 1.9.16.4SAFE ✓≥ 1.9.16.4
wps_hide_loginby wpserveur
AFFECTED< 1.9.16.4SAFE ✓≥ 1.9.16.4
Updated Aug 22, 2026View on NVD →
Detail

WPS Hide Login is a popular WordPress plugin that allows site administrators to hide and customize the login URL for enhanced security. It is used by website owners and developers to mitigate brute-force attacks by masking the login page. It is primarily installed on WordPress websites for added protection against unauthorized access. The plugin is widely used by both small businesses and large organizations managing WordPress-powered websites. By changing the default login URL, it reduces the chances of attackers targeting the login page directly.

The Path Traversal vulnerability in WPS Hide Login plugin allows unauthenticated users to access the hidden login page. It arises due to the plugin's failure to prevent redirects via the auth_redirect function. This flaw exposes WordPress sites using the plugin to unauthorized access attempts. It affects versions prior to 1.9.16.4.

The vulnerability resides in the auth_redirect function of the WPS Hide Login plugin. When this function is not adequately protected, attackers can exploit it to force a redirect, exposing the hidden login page. Affected versions do not block unauthenticated visitors from accessing this login page via specific crafted URLs. The plugin's security mechanism intended to hide the login page is bypassed, allowing unauthorized users to locate and potentially attempt brute-force login attacks. This issue is addressed in version 1.9.16.4.

If exploited, malicious users can discover the hidden login page, increasing the likelihood of brute-force attacks on WordPress websites. This can result in unauthorized access to the site's backend, allowing attackers to modify website content, steal sensitive data, or compromise the entire system. Furthermore, successful exploitation could lead to downtime or further exploitation of other vulnerabilities present on the site.

S4E platform offers comprehensive monitoring of your WordPress installations for vulnerabilities like the Path Traversal in WPS Hide Login. By using our platform, you can stay ahead of potential attackers, receive instant notifications of vulnerabilities, and access actionable remediation steps to protect your digital assets. Join S4E today to ensure your WordPress sites are secured from common and emerging threats, with real-time scans and a detailed reporting system.

References:

Solution Advice
  • Update the WPS Hide Login plugin to version 1.9.16.4 or later.
  • Ensure access controls are properly configured to restrict login page access.
  • Implement additional security measures like multi-factor authentication.
  • Regularly monitor WordPress plugins for known vulnerabilities.
  • Use strong, unique passwords to reduce the risk of brute-force attacks.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.