Understanding the Threat
The Change wp-admin Login WordPress plugin, a tool designed to enhance security by allowing users to modify their WordPress admin login URL, was found to have a significant security flaw. This vulnerability, identified as CVE-2022-1589, allowed unauthorized individuals to alter the plugin’s settings without needing to log in. This could lead to attackers changing critical settings, potentially impacting your website’s security and accessibility. The issue stemmed from a lack of proper authorization checks and missing Cross-Site Request Forgery (CSRF) protection when updating the plugin’s configuration.
CVE Details
- Product: Change wp-admin Login WordPress plugin
- Published Date: May 30, 2022
- Severity: High (CVSS: 7.5)
- Status: Analyzed
Affected Products
This vulnerability affects the Change wp-admin Login WordPress plugin. Specifically, any versions of the plugin prior to 1.1.0 are at risk.
Current Status
The vulnerability for CVE-2022-1589 has been thoroughly analyzed. This means the details of the flaw are well-understood and documented, allowing developers to create and distribute fixes.
Severity Level
Rated as High severity with a CVSS score of 7.5, this vulnerability indicates a serious risk. A High severity rating means that the flaw could be exploited relatively easily by an attacker and could lead to significant impact on the affected system. In this case, unauthorized changes to login settings could severely compromise a WordPress site’s administrative control.
Possible Solutions
To protect your WordPress website from this critical vulnerability, it is essential to update your Change wp-admin Login plugin immediately. The developers have released a fix in version 1.1.0. If you are running an older version, please update to 1.1.0 or newer as soon as possible. Regular updates are crucial for maintaining the security of your WordPress installations.
References
https://wpscan.com/vulnerability/257f9e14-4f43-4852-8384-80c15d087633
https://wpscan.com/vulnerability/257f9e14-4f43-4852-8384-80c15d087633


