CVE-2023-3604: Wpexperts All In One Login

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The Change WP Admin Login WordPress plugin before 1.1.4 discloses the URL of the hidden login page when accessing a crafted URL, bypassing the protection offered.

Affected products

  • Wpexperts All In One Login: before 1.1.4 (fixed in 1.1.4)

Published 2023-08-21. Last modified 2026-06-17.