CVE-2020-36710: medium-severity vulnerability in tabrisrp WPS Hide Login
WPS Hide Login <= 1.5.4.2 - Hidden Login Page Location Disclosure
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.8%
exploitation probability
0.8%top 46% of all CVEs
observed exploitation
nono source reports it
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected products
tabrisrp · WPS Hide LoginRelated CVEs — tabrisrp WPS Hide Login
In the same product, most dangerous first.