Executive brief
Easy Hide Login is a WordPress plugin that hides the standard login page behind a secret URL to prevent unauthorized access attempts. The plugin before version 1.7 fails to fully enforce this protection, allowing an unauthenticated attacker to access the login page through password-reset parameters and discover the secret login URL, completely defeating the plugin's core security feature.
Technical details
The plugin does not properly validate or restrict access to the standard WordPress login page when password-reset requests are made with certain parameters. An unauthenticated attacker can leverage this to bypass the hidden-login protection, reach the standard login page, and extract the configured secret login slug from the response. This is a sensitive data disclosure vulnerability (CWE-200) that undermines the plugin's primary protection mechanism.
Affected products
- Easy Hide Login Easy Hide Login before 1.7
Timeline
- 2026-09-21: disclosed
- 2026-09-21: patched: Fixed in version 1.7