ZeroHour

CVE-2023-5089

PoC ×2
CVSS 3.1
5.3 medium
EPSS
2%p82
Published
()
Modified
Description

The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

Vendors
wpmudev
Products
defender security
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.