CVERadar
Edition used by more than 30,000 companies in more than 150 countries.
Sign Up For FreeCVE-2024-2473
High Severity|Wpserveur
55
SVRS
5.3
CVSSv3
0.01235
EPSS
TAGS
In The Wild
VECTOR STRING
CVSS:3.1AV:NAC:LPR:NUI:NS:UC:LI:NA:N
PUBLICATION DATE2024-06-11
LAST MODIFIED2026-04-08
Security Intelligence Brief
1. What is this vulnerability and why does it matter?
This vulnerability, identified as CVE-2024-2473, is a Login Page Disclosure flaw affecting the WPS Hide Login plugin for WordPress. It matters because the core function of the plugin is to obscure the login page, thereby making it harder for attackers to find and target it. This vulnerability allows for a bypass of this hiding mechanism, making it trivial for attackers to discover the hidden login page. While not a direct exploit for gaining unauthorized access, it defeats a security measure and can serve as a precursor to other attacks, such as brute-force login attempts against the now-exposed login page.
2. What are the CVSS score, severity level, and disclosure details?
The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 5.3. Based on this score, the severity level is typically classified as Medium. The vulnerability was publicly published on June 11, 2024, at 02:01:58 UTC and was last modified on April 8, 2026, at 17:34:54 UTC.
3. Which products, vendors, systems, and versions are affected?
This vulnerability affects the WPS Hide Login plugin for WordPress. All versions of the plugin up to, and including, 1.9.15.2 are vulnerable. The affected system is WordPress, which hosts the vulnerable plugin.
4. What is the technical root cause and attack vector?
The technical root cause of this vulnerability is a bypass mechanism within the WPS Hide Login plugin. Specifically, when the 'action=postpass' parameter is supplied, it creates an unintended bypass that reveals the hidden login page. The attack vector involves an attacker sending a request that includes this specific parameter, thereby circumventing the plugin's intended functionality.
5. How can this vulnerability be exploited?
This vulnerability can be exploited by an attacker by simply supplying the 'action=postpass' parameter in a request to the WordPress site. This action bypasses the hiding mechanism implemented by the WPS Hide Login plugin, allowing the attacker to easily discover the custom login page URL that was meant to be hidden. Once discovered, the login page becomes a target for further attacks, such as credential stuffing or brute-force attempts.
6. What mitigation steps and patches are available?
The primary mitigation step is to update the WPS Hide Login plugin to a version beyond 1.9.15.2. As the vulnerability affects all versions up to and including 1.9.15.2, it is strongly recommended that users install a patched version released after 1.9.15.2 as soon as it becomes available from the plugin developer. Regularly checking for and applying plugin updates is crucial to ensure such vulnerabilities are addressed.
7. How can vulnerable systems be detected?
Vulnerable systems can be detected by identifying installations of the WPS Hide Login plugin on WordPress sites and checking their version number. Any installation running version 1.9.15.2 or earlier is considered vulnerable. System administrators should verify the version of all installed plugins within their WordPress environments.
10. What public intelligence references and advisories exist?
The primary public intelligence reference for this issue is CVE-2024-2473. Further advisories may be available from the plugin vendor or security researchers who have analyzed this specific CVE.
11. What is the risk assessment and urgency level?
The risk assessment for this vulnerability is considered Medium, as indicated by its CVSS score of 5.3. While it is not a direct execution vulnerability, it undermines a security control designed to obscure access points. The urgency level is Medium because the vulnerability makes the system more susceptible to follow-on attacks, such as brute-forcing credentials, by revealing the login page that was intended to be hidden. Organizations should prioritize updating the WPS Hide Login plugin to a patched version to restore the intended security posture and reduce the attack surface.
Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CREATE FREE ACCOUNTCVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.