Description
The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover the site's configured secret login slug from the returned page, defeating the Easy Hide Login WordPress plugin before 1.7's core protection.
Published: 2026-09-23
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Upgrade Plugin
AI Analysis

Impact

The Easy Hide Login WordPress plugin before version 1.7 does not fully enforce its hidden‑login protection. An unauthenticated attacker can reach the standard login page by sending specific password‑reset request parameters and, as a result, recover the site’s configured secret login slug from the returned page, thereby exposing sensitive URL information that defeats the core protection offered by the plugin.

Affected Systems

WordPress sites that are running Easy Hide Login versions earlier than 1.7 are affected. The vulnerability is specific to installations of this plugin and does not impact other WordPress components.

Risk and Exploitability

The vulnerability carries a CVSS score of 5.3, indicating medium severity, and an EPSS score of less than 1%, with no listing in CISA KEV. The attack vector is remote; exploitation requires only crafted HTTP requests to the password‑reset endpoint and does not need prior credentials. The disclosed secret login slug represents an information‑disclosure risk that could facilitate future credential-compromise attempts.

Generated by OpenCVE AI on September 23, 2026 at 15:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Easy Hide Login to version 1.7 or later promptly.
  • If updating is delayed, temporarily disable the Easy Hide Login plugin or remove it from the site to eliminate the hidden‑login feature.
  • Restrict or block access to the password‑reset endpoint through firewall or access‑control rules until the plugin can be updated.

Generated by OpenCVE AI on September 23, 2026 at 15:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover the site's configured secret login slug from the returned page, defeating the Easy Hide Login WordPress plugin before 1.7's core protection.
Title Easy Hide Login < 1.7 - Login Page Protection Bypass / Hidden URL Disclosure
Weaknesses CWE-200
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-23T10:57:07.158Z

Reserved: 2026-09-01T08:16:27.692Z

Link: CVE-2026-84168

cve-icon Vulnrichment

Updated: 2026-09-23T10:36:39.359Z

cve-icon NVD

Status : Received

Published: 2026-09-23T06:17:03.280

Modified: 2026-09-23T11:17:13.223

Link: CVE-2026-84168

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:30:07Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor