CVE-2026-84168

The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover the site's configured secret login slug from the returned page, defeating the Easy Hide Login WordPress plugin before 1.7's core protection.

  • Published Sep 23, 2026
  • CVSS 5.3 medium
  • 0.3% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-84168 at the National Vulnerability Database