WPS Hide Login < 1.9.1 - Protection Bypass with Referer-Header
40Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendepss 72%
from disclosure to weapon0 days
Published on NVDDec 6
metasploitOct 27
exploitation probability
72%top 1% of all CVEs
observed exploitation
nono source reports it
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
Affected products
Unknown · WPS Hide Login