Description
The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
Published: 2023-06-07
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-24152 The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.
History

Wed, 08 Apr 2026 17:45:00 +0000

Type Values Removed Values Added
Title WPS Hide Login <= 1.5.4.2 - Hidden Login Page Location Disclosure

Sat, 28 Dec 2024 02:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Wpserveur Wps Hide Login
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-04-08T17:01:48.320Z

Reserved: 2023-06-06T12:49:59.185Z

Link: CVE-2020-36710

cve-icon Vulnrichment

Updated: 2024-08-04T17:37:06.354Z

cve-icon NVD

Status : Modified

Published: 2023-06-07T02:15:11.637

Modified: 2026-04-08T18:17:08.780

Link: CVE-2020-36710

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses