LWS Hide Login

LWS Hide Login is a plugin that allows WordPress users to redirect their users if they try to access the admin page directly and choose their own link from their login page to protect their website. Users can also change the default redirection page and login address. The plugin is pre-installed in LWS web hosts and is released under the GNU General Public License.

This information is sourced from wpvulnerabilities.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Vulnerabilities

  • Weak configuration vulnerability in LWS Hide Login 2.1.8

    Fixed

    The LWS Hide Login plugin for WordPress is not secure in versions up to and including 2.1.8. This means that people who are not allowed to log in (known as attackers) can find a way around the hidden...

    Read More
  • Input validation vulnerability in LWS Hide Login 2.1.5

    Fixed

    The LWS Hide Login plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability exists in all versions of the plugin up to and including version 2.1.5....

    Read More
  • Access violation vulnerability in 6 plugins by LWS

    Fixed

    Several plugins for WordPress created by LWS (LWS Affiliation, LWS Optimize, LWS Tools, LWS Cleaner, LWS SMS and LWS Hide Login) have a security flaw which could allow attackers with at least subscri...

    Read More