Junglewise Threat Intelligence

CVE-2026-84168: Easy Hide Login WordPress plugin authentication bypass and hidden URL disclosure

CVE-2026-84168 · Severity: medium · CVSS 5.3 · Published 2026-09-23

Executive brief

Easy Hide Login is a WordPress plugin that hides the standard login page behind a secret URL to prevent unauthorized access attempts. The plugin before version 1.7 fails to fully enforce this protection, allowing an unauthenticated attacker to access the login page through password-reset parameters and discover the secret login URL, completely defeating the plugin's core security feature.

Technical details

The plugin does not properly validate or restrict access to the standard WordPress login page when password-reset requests are made with certain parameters. An unauthenticated attacker can leverage this to bypass the hidden-login protection, reach the standard login page, and extract the configured secret login slug from the response. This is a sensitive data disclosure vulnerability (CWE-200) that undermines the plugin's primary protection mechanism.

Affected products

  • Easy Hide Login Easy Hide Login before 1.7

Timeline

  • 2026-09-21: disclosed
  • 2026-09-21: patched: Fixed in version 1.7

References