← Vulnerability feed

Vulnerability record · CVE-2021-24917 · published 6 December 2021

CVE-2021-24917: WPS Hide Login plugin exposes secret login URL via unauthenticated request

Wpserveur · Wps Hide Login

The WPS Hide Login WordPress plugin before 1.9.1 fails to properly authorize requests to /wp-admin/options.php, letting an unauthenticated attacker retrieve the hidden custom login page URL by sending a request with an arbitrary Referer header. Because the plugin's whole purpose is to obscure the login endpoint, this flaw defeats that protection and re-exposes the standard authentication surface to automated scanning and brute force.

7.5 CVSS 3.1 High EPSS 72% · top 0.6% CWE-863 · Incorrect authorization
7.5CVSS 3.1 base score, v2 5.0
72%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: high.

high priorityUnauthenticated network-reachable information disclosure with a high EPSS score and public exploit references, though it only leaks the login URL rather than granting direct access.

What it is

The WPS Hide Login WordPress plugin before 1.9.1 fails to properly authorize requests to /wp-admin/options.php, letting an unauthenticated attacker retrieve the hidden custom login page URL by sending a request with an arbitrary Referer header. Because the plugin's whole purpose is to obscure the login endpoint, this flaw defeats that protection and re-exposes the standard authentication surface to automated scanning and brute force.

Impact

An attacker learns the secret login URL that the plugin was meant to hide, removing the obscurity barrier and enabling targeted credential attacks against the WordPress admin login. No data is directly modified; the gain is reconnaissance that weakens the site's login hardening.

Attack surface

Reachable over the network with no authentication and no user interaction: a single unauthenticated HTTP request to /wp-admin/options.php with a random Referer string triggers the disclosure. The CVSS vector confirms AV:N/AC:L/PR:N/UI:N.

Exploitation

Not listed in CISA KEV and no ransomware association, but EPSS is very high (0.715, ~99.4th percentile) and WPScan references are tagged Exploit, indicating public exploit detail exists.

What to do

  • Update WPS Hide Login to version 1.9.1 or later immediately.
  • If patching is delayed, restrict or block access to /wp-admin/options.php from untrusted sources at the web server or WAF.
  • Add rate limiting and lockout on the WordPress login endpoint once the real URL is known to be exposed.
  • Enforce strong unique admin credentials and multi-factor authentication on all WordPress accounts.
  • Audit logs for prior probing of /wp-admin/options.php to determine whether the hidden login URL was already harvested.

Detection

  • Alert on unauthenticated or anomalous requests to /wp-admin/options.php, especially with unusual or random Referer headers.
  • Monitor web logs for sequential scanning of /wp-admin/options.php followed by login attempts against a non-default path.
  • Track failed login spikes against wp-login.php or custom login slugs from single source IPs.
  • Review WordPress plugin inventory for WPS Hide Login versions below 1.9.1.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-24917 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-15826Wpserveur wps hide login vulnerabilityThe wps-hide-login plugin before 1.5.3 for WordPress has a protection bypass via wp-login.php in the Referer field.EPSS 3.0%9.8CVE-2019-15823Wpserveur wps hide login vulnerabilityThe wps-hide-login plugin before 1.5.3 for WordPress has an action=confirmaction protection bypass.EPSS 8.6%9.8CVE-2019-15824Wpserveur wps hide login vulnerabilityThe wps-hide-login plugin before 1.5.3 for WordPress has an adminhash protection bypass.EPSS 3.0%9.8CVE-2019-15825Wpserveur wps hide login vulnerabilityThe wps-hide-login plugin before 1.5.3 for WordPress has an action=rp&key&login protection bypass.EPSS 3.0%8.8CVE-2015-9498Wpserveur wps hide login cross-site request forgery vulnerabilityThe wps-hide-login plugin before 1.1 for WordPress has CSRF that affects saving an option value.EPSS 0.72%7.5CVE-2020-36710Wpserveur wps hide login incorrect authorization vulnerabilityThe WPS Hide Login plugin for WordPress is vulnerable to login page disclosure even when the settings of the plugin are set to hide the login page ma…EPSS 0.78%6.1CVE-2024-6289Wpserveur wps hide login open redirect vulnerabilityThe WPS Hide Login WordPress plugin before 1.9.16.4 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing a…EPSS 0.90%5.3CVE-2024-2473Wpserveur wps hide login incorrect authorization vulnerabilityThe WPS Hide Login plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 1.9.15.2. This is due to a bypas…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2021-24917), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.