Home » Security News » Vulnerability in WPS Hide Login plugin leaves over...

Vulnerability in WPS Hide Login plugin leaves over a million WordPress websites at risk

Vulnerability in WPS Hide Login plugin leaves over a million WordPress websites at risk
Deepanker Verma December 14, 2021 Security

Add Techlomedia as a preferred source on Google. Preferred Source

WPS Hide Login recently patched a vulnerability that could expose the website’s secret login page. The vulnerability allows a malicious hacker to easily find the login page and then use Bruteforce or other mechanisms against the website. So, the vulnerability completely defeats the purpose of the plugin itself that claims to hide the login page.

Also see: Best Hacking Apps for Android

WPS Hide Login is a quite popular plugin with over one million installed. If you also use this plugin on your WordPress website, you need to update the plugin to the latest version.

According to the WPS Login Changelog:

“1.9.1
Fix : by-pass security issue allowing an unauthenticated user to get login page by setting a random referer string via curl request.

page by setting a random referer string via curl request.”

The vulnerability was publicly reported on the plugin’s support page. Later, WPScan also published a proof of concept to show how the vulnerability is real.

WordPress is a popular content management system used by millions of websites. So, several hacking tools exist that claim to crack WordPress login using different methods. That’s the reason people use the WPS Hide Login plugin to hide the login page from malicious bots and users. WordPress login page usually exists at /wp-login.php, but you can use the plugin to change it to /some-folder/wp-login.php or anything you want.

Follow Techlomedia on Google News to stay updated. Follow on Google News

Affiliate Disclosure:

This article may contain affiliate links. We may earn a commission on purchases made through these links at no extra cost to you.

Deepanker Verma

About the Author: Deepanker Verma

Deepanker Verma is the Founder and Editor-in-Chief of TechloMedia. He holds Engineering degree in Computer Science and has over 15 years of experience in the technology sector. Deepanker bridges the gap between complex engineering and consumer electronics. He is also a a known Security Researcher acknowledged by global giants including Apple, Microsoft, and eBay. He uses his technical background to rigorously test gadgets, focusing on performance, security, and long-term value.

Related Posts

Stay Updated with Techlomedia

Join our newsletter to receive the latest tech news, reviews, and guides directly in your inbox.