Weak configuration vulnerability in Defender Security – Malware Scanner, Login Security & Firewall 4.0.2

The Defender Security plugin for WordPress is vulnerable to a protection bypass in versions up to 4.0.2. This means that unauthenticated attackers can get around the ‘Hide Login Page’ security feature. This is caused by the plugin not stopping redirects from the auth_redirect WordPress function.

Detected in:

Defender Security – Malware Scanner, Login Security & Firewall fixed vulnerable versions: >= * <= 4.0.2

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.