Impact
The Easy Hide Login WordPress plugin before version 1.7 does not fully enforce its hidden‑login protection. An unauthenticated attacker can reach the standard login page by sending specific password‑reset request parameters and, as a result, recover the site’s configured secret login slug from the returned page, thereby exposing sensitive URL information that defeats the core protection offered by the plugin.
Affected Systems
WordPress sites that are running Easy Hide Login versions earlier than 1.7 are affected. The vulnerability is specific to installations of this plugin and does not impact other WordPress components.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.3, indicating medium severity, and an EPSS score of less than 1%, with no listing in CISA KEV. The attack vector is remote; exploitation requires only crafted HTTP requests to the password‑reset endpoint and does not need prior credentials. The disclosed secret login slug represents an information‑disclosure risk that could facilitate future credential-compromise attempts.
OpenCVE Enrichment