Vulnerabilities (CVE)

Filtered by vendor Wpserveur Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2021-24917 1 Wpserveur 1 Wps Hide Login 2022-01-03 5.0 MEDIUM 7.5 HIGH
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
CVE-2015-9498 1 Wpserveur 1 Wps Hide Login 2019-10-24 6.8 MEDIUM 8.8 HIGH
The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.