CVE-2026-84168: Unknown Easy Hide Login

Medium severity, CVSS 5.3. EPSS: 0.3% chance of exploitation in the next 30 days.

The Easy Hide Login WordPress plugin before 1.7 does not fully enforce its hidden-login protection, allowing an unauthenticated attacker to reach the standard login page through certain password-reset request parameters and to recover the site's configured secret login slug from the returned page, defeating the Easy Hide Login WordPress plugin before 1.7's core protection.

Affected products

  • Unknown Easy Hide Login: before 1.7 (fixed in 1.7)

Published 2026-09-23. Last modified 2026-09-23.