CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 7.5. It affects WordPress. Its EPSS score suggests a 71.5% probability of exploitation in the next 30 days. Exploitation may require the attacker to be authenticated.
CVE
CVE-2021-24917
Severity
HIGH
CVSS
7.5
EPSS
71.53%
WordPress
Original NVD Description
The WPS Hide Login WordPress plugin before 1.9.1 has a bug which allows to get the secret login page by setting a random referer string and making a request to /wp-admin/options.php as an unauthenticated user.
Related CVEs
Other vulnerabilities affecting the same vendor(s)