Yet another WordPress plugin vulnerability leaves over one million websites exposed

Person editing a WordPress site
(Image credit: Pixabay)

A new WordPress plugin vulnerability has been discovered that could allow an attacker to gain access to a site's administrator login page.

The vulnerability exists in the popular WPS Hide Login plugin and was discovered by a user with the handle thalakus who posted a brief description of the issue on WordPress.org's support forum. 

Ironically, this vulnerability defeats the purpose of the plugin which hides a WordPress site's administrator login page and makes the wp-admin directory inaccessible.

As over one million WordPress sites use WPS Hide Login to add a deeper layer of security, users of this plugin should upgrade to the latest version now to prevent any attackers from exploiting this vulnerability.

Hiding the administrator login page

While WPS Hide Login and can be used to hide a site's administrator login page, there's actually another way to do so without having to install a separate WordPress plugin according to Search Engine Journal.

As hackers and bots trying to attack a WordPress site's login page often look in its default location, installing WordPress into a directory folder with a random name can be used to achieve the same outcome. So instead of housing the login page at /wp-login.php, you can install it into a directory folder with a random name so it appears like this instead: /random-file-name/wp-login.php.

Still though, the WPS Hide Login WordPress plugin can be useful for sites that already have WordPress installed at the root directory.

The creator of the plugin, Nicolas Kulka, has now fixed the issue and WPS Hide Login users should upgrade the plugin to version 1.9.1 to secure their sites from any potential attacks exploiting this vulnerability.

We've also rounded up the best WordPress plugins, best WordPress hosting and best web hosting services

Via Search Engine Journal

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Read more
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Over a million WordPress sites exposed to attack from W3 Total Cache plugin flaw
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Another serious WordPress plugin vulnerability could put 40,000 sites at risk of attack
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
Thousands of WordPress websites hit in new malware attack, here's what we know
Wordpress brand logo on computer screen. Man typing on the keyboard.
Thousands of WordPress sites targeted with malicious plugin backdoor attacks
WordPress
WordPress users beware - these popular theme plugins have some major security issues
Latest in Security
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Google Chrome
Google Chrome security flaw could have let hackers spy on all your online habits
Latest in News
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently making a major announcement about Avengers: Doomsday's cast on YouTube, and I think it's going to be a long-winded reveal
Samsung QN90F on yellow background
Samsung announces US prices for its 2025 mini-LED TV lineup, and it’s good and bad news
Nintendo Switch Lite
Forget the Nintendo Switch 2, the original Switch is getting one last hurrah in a surprise Nintendo Direct tomorrow
The Samsung Galaxy S25 Edge on display the January 22, 2025 Galaxy Unpacked event.
Samsung Galaxy S25 Edge colors seemingly revealed in new video, and there’s another sign of an imminent launch