CVE-2023-3139observed exploitation

CVE-2023-3139: vulnerability in Protect WP Admin

Protect WP Admin < 4.0 - Unauthenticated Protection Bypass

Published · Updated

40Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actepss 0.7%
from disclosure to weapon
Published on NVDJul 4
VulnCheckJun 22
exploitation probability
0.7%top 47% of all CVEs
observed exploitation
yesVulnCheck
The Protect WP Admin WordPress plugin before 4.0 discloses the URL of the admin panel via a redirection of a crafted URL, bypassing the protection offered.
Related CVEs — Protect WP Admin

In the same product, most dangerous first.