WpserveurCVEs & Vulnerabilities

11 CVEs affecting Wpserveur products, tracked from the National Vulnerability Database, with CVSS/EPSS scores and exploitation status.

Most Affected Products

wps hide login 10wps child theme generator 1
CVE-2024-2473KEVMEDIUMin the wild

The WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypass that is created when the 'action=postpass' parameter is supplied. This makes it possible for attackers to easily discover any login page that may have been hidden by the plugin.

11 Apr 2026
5.3
CVSS
CVE-2024-6289MEDIUM

The WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

15 Jul 2024
6.1
CVSS
CVE-2020-36710HIGH

The WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page making it possible for unauthenticated attackers to brute force credentials on sites in versions up to, and including, 1.5.4.2.

7 Jun 2023
7.5
CVSS
CVE-2021-24917HIGH

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

6 Dec 2021
7.5
CVSS
CVE-2021-3332MEDIUM

WPS Hide Login 1.6.1 allows remote attackers to bypass a protection mechanism via post_password.

2 Mar 2021
5.3
CVSS
CVE-2015-9498HIGH

The wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.

23 Oct 2019
8.8
CVSS
CVE-2019-15826CRITICAL

The wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.

30 Aug 2019
9.8
CVSS
CVE-2019-15825CRITICAL

The wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.

30 Aug 2019
9.8
CVSS
CVE-2019-15824CRITICAL

The wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.

30 Aug 2019
9.8
CVSS
CVE-2019-15823CRITICAL

The wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.

30 Aug 2019
9.8
CVSS
CVE-2019-15822CRITICAL

The wps-child-theme-generator plugin before 1.2 for WordPress has classes/helpers.php directory traversal.

30 Aug 2019
9.8
CVSS
← PrevPage 1 / 1Next →