CVE-2020-36710mediumCWE-863

CVE-2020-36710: medium-severity vulnerability in tabrisrp WPS Hide Login

WPS Hide Login <= 1.5.4.2 - Hidden Login Page Location Disclosure

Published · Updated

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 5.3epss 0.8%
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Related CVEs — tabrisrp WPS Hide Login

In the same product, most dangerous first.