Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover the site's configured secret login slug from the returned page, defeating the Easy Hide Login WordPress plugin before 1.7's core protection. | |
| Title | Easy Hide Login < 1.7 - Login Page Protection Bypass / Hidden URL Disclosure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-23T10:57:07.158Z
Reserved: 2026-09-01T08:16:27.692Z
Link: CVE-2026-84168
Updated: 2026-09-23T10:36:39.359Z
Status : Received
Published: 2026-09-23T06:17:03.280
Modified: 2026-09-23T11:17:13.223
Link: CVE-2026-84168
No data.
OpenCVE Enrichment
No data.