← back
CVE-2023-3139observed exploitation

Protect WP Admin < 4.0 - Unauthenticated Protection Bypass

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 0.7%
from disclosure to weapon
Published on NVDJul 4
VulnCheckJun 22
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
yesVulnCheck
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.