CVE-2023-5089: Wpmudev Defender Security
Medium severity, CVSS 5.3. EPSS: 2.2% chance of exploitation in the next 30 days.
The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.
Affected products
- Wpmudev Defender Security: before 4.1.0 (fixed in 4.1.0)
Published 2023-10-16. Last modified 2026-06-17.