CVE Radar

CVE Radar Logo
CVERadar

Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For Free

CVE-2024-2473

High Severity|Wpserveur
55
SVRS
5.3
CVSSv3
0.01235
EPSS
TAGS
In The Wild
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:NS:UC:LI:NA:N
PUBLICATION DATE2024-06-11
LAST MODIFIED2026-04-08

Security Intelligence Brief

1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-2473, is a Login Page Disclosure flaw affecting the WPS Hide Login plugin for WordPress. It matters because the core function of the plugin is to obscure the login page, thereby making it harder for attackers to find and target it. This vulnerability allows for a bypass of this hiding mechanism, making it trivial for attackers to discover the hidden login page. While not a direct exploit for gaining unauthorized access, it defeats a security measure and can serve as a precursor to other attacks, such as brute-force login attempts against the now-exposed login page.
2. What are the CVSS score, severity level, and disclosure details?
The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.3. Based on this score, the severity level is typically classified as Medium. The vulnerability was publicly published on June 11, 2024, at 02:01:58 UTC and was last modified on April 8, 2026, at 17:34:54 UTC.
3. Which products, vendors, systems, and versions are affected?
This vulnerability affects the WPS Hide Login plugin for WordPress. All versions of the plugin up to, and including, 1.9.15.2 are vulnerable. The affected system is WordPress, which hosts the vulnerable plugin.
4. What is the technical root cause and attack vector?
The technical root cause of this vulnerability is a bypass mechanism within the WPS Hide Login plugin. Specifically, when the 'action=postpass' parameter is supplied, it creates an unintended bypass that reveals the hidden login page. The attack vector involves an attacker sending a request that includes this specific parameter, thereby circumventing the plugin's intended functionality.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker by simply supplying the 'action=postpass' parameter in a request to the WordPress site. This action bypasses the hiding mechanism implemented by the WPS Hide Login plugin, allowing the attacker to easily discover the custom login page URL that was meant to be hidden. Once discovered, the login page becomes a target for further attacks, such as credential stuffing or brute-force attempts.
6. What mitigation steps and patches are available?
The primary mitigation step is to update the WPS Hide Login plugin to a version beyond 1.9.15.2. As the vulnerability affects all versions up to and including 1.9.15.2, it is strongly recommended that users install a patched version released after 1.9.15.2 as soon as it becomes available from the plugin developer. Regularly checking for and applying plugin updates is crucial to ensure such vulnerabilities are addressed.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by identifying installations of the WPS Hide Login plugin on WordPress sites and checking their version number. Any installation running version 1.9.15.2 or earlier is considered vulnerable. System administrators should verify the version of all installed plugins within their WordPress environments.
10. What public intelligence references and advisories exist?
The primary public intelligence reference for this issue is CVE-2024-2473. Further advisories may be available from the plugin vendor or security researchers who have analyzed this specific CVE.
11. What is the risk assessment and urgency level?
The risk assessment for this vulnerability is considered Medium, as indicated by its CVSS score of 5.3. While it is not a direct execution vulnerability, it undermines a security control designed to obscure access points. The urgency level is Medium because the vulnerability makes the system more susceptible to follow-on attacks, such as brute-forcing credentials, by revealing the login page that was intended to be hidden. Organizations should prioritize updating the WPS Hide Login plugin to a patched version to restore the intended security posture and reduce the attack surface.

No IOCs found for this CVE

No exploits found for this CVE

SOCRadar Logo

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence

Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.

CREATE FREE ACCOUNT
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs
CVE-2024-2473 | WPS Hide Login Plugin up to 1.9.15.2 on WordPress Login Page information disclosure
vuldb.com2026-07-13
CVE-2024-2473 | WPS Hide Login Plugin up to 1.9.15.2 on WordPress Login Page information disclosure | A vulnerability described as problematic has been identified in WPS Hide Login Plugin up to 1.9.15.2 on WordPress. Affected by this issue is some unknown functionality of the component Login Page. Executing a manipulation can lead to information disclosure. The identification of this vulnerability is CVE-2024-2473
cve-2024-2473wordpressleadgt

No tweets found for this CVE

Configuration 1
TypeVendorProduct
AppWpserveurwps_hide_login
ReferenceLink
[email protected]https://plugins.trac.wordpress.org/changeset/3099109/wps-hide-login
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/fd21c7d3-a5f1-4c3a-b6ab-0a979f070a62?source=cve
AF854A3A-2127-422B-91AE-364DA2661108https://www.wordfence.com/threat-intel/vulnerabilities/id/fd21c7d3-a5f1-4c3a-b6ab-0a979f070a62?source=cve
[email protected]https://github.com/whattheslime/wps-show-login
[email protected]https://www.wordfence.com/threat-intel/vulnerabilities/id/fd21c7d3-a5f1-4c3a-b6ab-0a979f070a62?source=cve
CWE IDCWE NameDescription
CWE-863Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.