CVE-2023-5089: Wpmudev Defender Security

Medium severity, CVSS 5.3. EPSS: 2.2% chance of exploitation in the next 30 days.

The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

Affected products

  • Wpmudev Defender Security: before 4.1.0 (fixed in 4.1.0)

Published 2023-10-16. Last modified 2026-06-17.