The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 23 Apr 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-04-23T16:10:59.957Z
Reserved: 2023-09-20T14:56:32.290Z
Link: CVE-2023-5089
Updated: 2024-08-02T07:44:53.860Z
Status : Modified
Published: 2023-10-16T20:15:17.737
Modified: 2025-04-23T17:16:49.590
Link: CVE-2023-5089
No data.
OpenCVE Enrichment
No data.
Weaknesses
No weakness.