Input validation vulnerability in LWS Hide Login 2.1.5

The LWS Hide Login plugin for WordPress is vulnerable to a type of attack called Cross-Site Request Forgery. This vulnerability exists in all versions of the plugin up to and including version 2.1.5. This means that an unauthenticated attacker could potentially send a malicious link to a site administrator, who, if they clicked on it, would unknowingly perform an action. This is because the plugin fails to properly validate the nonce (a security key) on one of its functions.

Detected in:

LWS Hide Login fixed vulnerable versions: >= * <= 2.1.6

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.