Access violation vulnerability in HC Custom WP-Admin URL 1.4

HC Custom WP-Admin URL versions up to 1.4 have a vulnerability that allows unauthenticated attackers to change the login page address. This vulnerability exists because the plugin sets the address for the login page without first checking if the user is authorized to do so.

Detected in:

HC Custom WP-Admin URL open vulnerable versions: >= * <= 1.4

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.