Skip to content
No results
Menu
Web Hosting and IT Consultancy ServicesWeb Hosting and IT Consultancy Services
  • About Us
  • Blog
  • Payment Option
  • Support
  • We are hiring
Sign Up
  • Home
  • Security
  • Release
Web Hosting and IT Consultancy ServicesWeb Hosting and IT Consultancy Services

Change WP Admin Login Plugin Information Disclosure Vulnerability (CVE-2023-3604) — High Severity

  • Alex JosephAlex Joseph
  • January 14, 2026
  • Security

WordPress users often rely on plugins to enhance their site’s security, like hiding the default admin login page. However, a significant security flaw has been found in the popular “Change WP Admin Login” plugin, which could expose your hidden login page. This vulnerability, identified as CVE-2023-3604, is rated as high severity and impacts versions prior to 1.1.4. It’s crucial for website administrators and developers to understand this risk and take immediate action.

CVE Details

This security issue affects the Change WP Admin Login WordPress plugin.

  • CVE ID: CVE-2023-3604
  • Published Date: August 21, 2023
  • Severity: High
  • Status: Analyzed

Affected Products

The vulnerability specifically impacts the Change WP Admin Login WordPress plugin versions earlier than 1.1.4. If you are using any version older than 1.1.4, your website is at risk.

Current Status

The vulnerability is currently “Analyzed,” meaning its details have been investigated and confirmed. This information is now publicly available, making it even more important for users to apply the necessary fixes.

Severity Level

Rated as “High” severity, this information disclosure vulnerability should not be taken lightly. While it doesn’t directly allow an attacker to log in, it defeats the primary purpose of the plugin: to hide your custom admin login URL. Knowing the login page URL makes it easier for attackers to launch brute-force attacks or other targeted attacks against your WordPress site’s administration area. This can lead to unauthorized access if weak passwords are in use.

Possible Solutions

The good news is that a fix is available! To protect your WordPress site from CVE-2023-3604, you must update the Change WP Admin Login plugin to version 1.1.4 or higher. This updated version addresses the flaw that was exposing the hidden login page URL.

Here’s how to update your plugin:

  1. Log in to your WordPress admin dashboard.
  2. Navigate to “Plugins” -> “Installed Plugins”.
  3. Locate “Change WP Admin Login” in the list.
  4. If an update is available, you will see a notification. Click on “Update Now”.
  5. Always back up your website before performing any updates to avoid data loss.

If for some reason you cannot update immediately, consider temporarily deactivating the plugin until you can apply the patch. However, updating is the strongest recommendation.

References

https://wpscan.com/vulnerability/8f6615e8-f607-4ce4-a0e0-d5fc841ead16
https://wpscan.com/vulnerability/8f6615e8-f607-4ce4-a0e0-d5fc841ead16

Tags
# Change Wp Admin Login# Information Disclosure# Plugin Security# WordPress# WordPress Plugin
Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.

Previous Post URL Params WordPress Plugin Stored XSS Vulnerability (CVE-2023-0274) — Medium Severity
Next Post Change wp-admin Login Unauthenticated Arbitrary Settings Update Vulnerability (CVE-2022-1589) — High Severity

Recent Posts

  • n8n Credential Authorization Bypass Vulnerability (CVE-2026-72774) — Medium Severity
  • n8n Account Takeover Vulnerability (CVE-2026-72772) — High Severity
  • n8n Prototype Pollution Vulnerability (CVE-2026-72769) — High Severity
  • n8n Remote Code Execution Vulnerability (CVE-2026-72767) — High Severity
  • n8n Module Cache Poisoning Vulnerability (CVE-2026-72764) — HIGH Severity

Related Posts

n8n Credential Authorization Bypass Vulnerability (CVE-2026-72774) — Medium Severity

  • Alex Joseph
  • September 19, 2026

n8n Account Takeover Vulnerability (CVE-2026-72772) — High Severity

  • Alex Joseph
  • September 18, 2026

n8n Prototype Pollution Vulnerability (CVE-2026-72769) — High Severity

  • Alex Joseph
  • September 18, 2026

Servers

  • Self Managed Dedicated Server
  • Managed Dedicated Server
  • Low Cost Dedicated Server
  • Gaming Dedicated Server
  • Dedicated server for Siberian CMS
  • Shoutcast Dedicated Server
  • Flussonic Dedicated Server

Servers Locations

  • Dedicated Servers in India
  • Dedicated Servers in China
  • Dedicated Servers in Russia
  • Dedicated Servers in Canada
  • Dedicated Servers in UK
  • Dedicated Servers in Turkey
  • Dedicated Servers in Japan

Hosting

  • Web Hosting
  • Premium cPanel Hosting
  • Reseller Hosting
  • Shared Hosting
  • Shoutcast Hosting
  • Online Radio Hosting

Solutions

  • Software Installations
  • Hire an Expert
  • Server Monitoring
  • Server Administrators
  • Hosting Support
  • cPanel Management

The Ucartz Online Pvt. Ltd. incorporated under the Ministry of Corporate Affairs, India [CIN: U72200KL2017PTC048470] and the GST Identification Number: 32AACCU0519P1ZA. By using this site, you signify that you agree to be bound by Ucartz TOS.