Input validation vulnerability in Easy Hide Login 1.0.8

The Easy Hide Login plugin for WordPress has an issue that affects its security in versions up to 1.0.8. This issue is called Cross-Site Request Forgery and it is caused by the plugin’s failure to carry out a necessary security check (called nonce validation) on the wp_hide_login_plugin_options function. This means that if someone is able to trick an administrator into clicking a link, they can change the plugin’s settings without having to authenticate themselves.

Detected in:

Easy Hide Login fixed vulnerable versions: >= * <= 1.0.8

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.