Vulnerability record · CVE-2021-24917 · published 6 December 2021
CVE-2021-24917: WPS Hide Login plugin exposes secret login URL via unauthenticated request
Wpserveur · Wps Hide Login
The WPS Hide Login WordPress plugin before 1.9.1 fails to properly authorize requests to /wp-admin/options.php, letting an unauthenticated attacker retrieve the hidden custom login page URL by sending a request with an arbitrary Referer header. Because the plugin's whole purpose is to obscure the login endpoint, this flaw defeats that protection and re-exposes the standard authentication surface to automated scanning and brute force.
Description
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Automated analysis
high priorityUnauthenticated network-reachable information disclosure with a high EPSS score and public exploit references, though it only leaks the login URL rather than granting direct access.
What it is
The WPS Hide Login WordPress plugin before 1.9.1 fails to properly authorize requests to /wp-admin/options.php, letting an unauthenticated attacker retrieve the hidden custom login page URL by sending a request with an arbitrary Referer header. Because the plugin's whole purpose is to obscure the login endpoint, this flaw defeats that protection and re-exposes the standard authentication surface to automated scanning and brute force.
Impact
An attacker learns the secret login URL that the plugin was meant to hide, removing the obscurity barrier and enabling targeted credential attacks against the WordPress admin login. No data is directly modified; the gain is reconnaissance that weakens the site's login hardening.
Attack surface
Reachable over the network with no authentication and no user interaction: a single unauthenticated HTTP request to /wp-admin/options.php with a random Referer string triggers the disclosure. The CVSS vector confirms AV:N/AC:L/PR:N/UI:N.
Exploitation
Not listed in CISA KEV and no ransomware association, but EPSS is very high (0.715, ~99.4th percentile) and WPScan references are tagged Exploit, indicating public exploit detail exists.
What to do
- Update WPS Hide Login to version 1.9.1 or later immediately.
- If patching is delayed, restrict or block access to /wp-admin/options.php from untrusted sources at the web server or WAF.
- Add rate limiting and lockout on the WordPress login endpoint once the real URL is known to be exposed.
- Enforce strong unique admin credentials and multi-factor authentication on all WordPress accounts.
- Audit logs for prior probing of /wp-admin/options.php to determine whether the hidden login URL was already harvested.
Detection
- Alert on unauthenticated or anomalous requests to /wp-admin/options.php, especially with unusual or random Referer headers.
- Monitor web logs for sequential scanning of /wp-admin/options.php followed by login attempts against a non-default path.
- Track failed login spikes against wp-login.php or custom login slugs from single source IPs.
- Review WordPress plugin inventory for WPS Hide Login versions below 1.9.1.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wordpress.org/support/topic/bypass-security-issue/ | Third Party Advisory |
| https://wpscan.com/vulnerability/15bb711a-7d70-4891-b7a2-c473e3e8b375 | ExploitThird Party Advisory |
| https://wordpress.org/support/topic/bypass-security-issue/ | Third Party Advisory |
| https://wpscan.com/vulnerability/15bb711a-7d70-4891-b7a2-c473e3e8b375 | ExploitThird Party Advisory |
Track CVE-2021-24917 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-24917), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.