Make WordPress Core

Opened 7 years ago

Closed 7 years ago

#46953 closed defect (bug) (invalid)

Plugin disclosing the hidden login page

Reported by: hackison's profile hackison Owned by:
Milestone: Priority: normal
Severity: normal Version:
Component: Plugins Keywords:
Focuses: privacy Cc:

Description

Im having my own wordpress website with Wp hide login plugin installed. Recently i was testing my website in an online osint website https://urlscan.io/. The result was shocking in the content tab , my hidden login form is disclosed. Login form is disclosing through buddy press plugin.This occurs due to incompatibility between buddypress plugin and wp hide login plugin.Please fix it asap Thank you

STEPS TO REPRODUCE:

1) Go to https://urlscan.io/ website.
2) In the search bar type the website you want to get the hidden login form.
3) Wait till the scan completes.
4) Now result will be displayed move to content tab.
5) You can see the hiden login form details getting disclosed.

Attachments (1)

wpshidelogin.mkv (3.0 MB) - added by hackison 7 years ago.

Change History (2)

@hackison
7 years ago

#1 @SergeyBiryukov
7 years ago

  • Keywords needs-patch removed
  • Milestone Awaiting Review deleted
  • Resolution set to invalid
  • Severity changed from critical to normal
  • Status changed from new to closed

Hi @hackison, welcome to WordPress Trac! Thanks for the ticket.

I'm sorry to hear you are having issues with WordPress. Please note that this Trac is used for enhancements and bug reporting for the WordPress core software, not for third-party plugins like WPS Hide Login or individual support questions. Please try the support forums to get help with your site: https://wordpress.org/support/.

Note: See TracTickets for help on using tickets.