WordPress users often rely on plugins to enhance their site’s security, like hiding the default admin login page. However, a significant security flaw has been found in the popular “Change WP Admin Login” plugin, which could expose your hidden login page. This vulnerability, identified as CVE-2023-3604, is rated as high severity and impacts versions prior to 1.1.4. It’s crucial for website administrators and developers to understand this risk and take immediate action.
CVE Details
This security issue affects the Change WP Admin Login WordPress plugin.
- CVE ID: CVE-2023-3604
- Published Date: August 21, 2023
- Severity: High
- Status: Analyzed
Affected Products
The vulnerability specifically impacts the Change WP Admin Login WordPress plugin versions earlier than 1.1.4. If you are using any version older than 1.1.4, your website is at risk.
Current Status
The vulnerability is currently “Analyzed,” meaning its details have been investigated and confirmed. This information is now publicly available, making it even more important for users to apply the necessary fixes.
Severity Level
Rated as “High” severity, this information disclosure vulnerability should not be taken lightly. While it doesn’t directly allow an attacker to log in, it defeats the primary purpose of the plugin: to hide your custom admin login URL. Knowing the login page URL makes it easier for attackers to launch brute-force attacks or other targeted attacks against your WordPress site’s administration area. This can lead to unauthorized access if weak passwords are in use.
Possible Solutions
The good news is that a fix is available! To protect your WordPress site from CVE-2023-3604, you must update the Change WP Admin Login plugin to version 1.1.4 or higher. This updated version addresses the flaw that was exposing the hidden login page URL.
Here’s how to update your plugin:
- Log in to your WordPress admin dashboard.
- Navigate to “Plugins” -> “Installed Plugins”.
- Locate “Change WP Admin Login” in the list.
- If an update is available, you will see a notification. Click on “Update Now”.
- Always back up your website before performing any updates to avoid data loss.
If for some reason you cannot update immediately, consider temporarily deactivating the plugin until you can apply the patch. However, updating is the strongest recommendation.
References
https://wpscan.com/vulnerability/8f6615e8-f607-4ce4-a0e0-d5fc841ead16
https://wpscan.com/vulnerability/8f6615e8-f607-4ce4-a0e0-d5fc841ead16


