The Rename wp-login.php WordPress plugin through 2.6.0 does not have CSRF check in place when updating the secret login URL, which could allow attackers to make a logged in admin change them via a CSRF attack
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: WPScan
Published: 2022-07-11T12:56:10
Updated: 2024-08-03T00:16:59.695Z
Reserved: 2022-05-16T00:00:00
Link: CVE-2022-1732
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2022-07-11T13:15:08.650
Modified: 2022-07-15T19:16:45.133
Link: CVE-2022-1732
Redhat
No data.