Login

Plugin Vulnerabilities

A service to protect your site against vulnerabilities in WordPress plugins.

  • Why Plugin Vulnerabilities?
    • We Provide Fixes for Vulnerabilities
    • We Provide Accurate Vulnerability Information
    • Insightful Blocked Exploit Attempt Reporting
    • How We Are Improving the Security of WordPress Plugins
    • Proactive Monitoring for Vulnerabilities in New Versions of WordPress Plugins
    • Select Plugins to Receive Security Reviews
  • Sign Up
    • Set Up
  • PV Firewall
    • Set Up
    • Block Insights
    • WordPress Firewall Comparison
  • Other Services
    • WordPress Security Checkup
    • Plugin Security Review
    • Continuous Plugin Security Review Service
    • Theme Security Review
    • Hacked WordPress Website Cleanup
    • Abandoned WordPress Plugin Maintenance Service
    • Blue Hat Hacking Service for WordPress Plugins/Websites
    • Plugin Vulnerabilities Subscription for ClassicPress
    • Solutions for Web Hosts
    • Solutions for Security Providers
  • Plugin Search
    • WordPress Firewall Tester
    • WordPress Plugins Checker
    • Plugin Security Scorecard
    • Security Scorecard WordPress Plugin
    • WordPress REST API Route Checker
  • Research
    • Plugin Vulnerabilities Survey
    • Report Hacking of WordPress Website
    • Unfixed Security Issues in WordPress
    • Security Advisories on WordPress Plugin Developers
    • WP Security Researcher Database
    • Send us a Tip
  • About
    • WordPress Plugin Zero-Day Vulnerability Exploitation Info Sharing Partnership
    • Get Free Help Fixing A Security Vulnerability In Your WordPress Plugin
    • Contact Us
    • Feedback
    • Report a WordPress Plugin Vulnerability We Are Missing

Tag Archives: Easy Hide Login

8 Jun 2021

Unnecessary WordPress Security Plugin With 40,000+ Installs Contains Vulnerability Due to Poor Security

It doesn’t seem like it is too much to expect that a WordPress security plugin would not make your website less secure. But that is exactly what the plugin Easy Hide Login, which has 40,000+ active installations according to wordpress.org, does. The plugin “hides” WordPress’ login page, which isn’t something that you actually need to security wise. Since this isn’t something that you need to do, it really shouldn’t be surprising that someone developing such a plugin wouldn’t have a great understanding of security and that is the case with this plugin (and others in the past, as well).

We came across this plugin while looking for code relevant to an improvement to our Plugin Security Checker tool’s ability to detect issues with SQL injection, which is insecure code related to making queries of a database. The plugin’s code that came across while doing that doesn’t really make sense, as the plugin escapes its setting using esc_sql(), which is for escaping a value being used in a SQL statement: [Read more]

Plugin Vulnerabilities Posted in Vulnerability Report Cross-Site Request Forgery (CSRF)/Cross-Site Scripting (XSS), Easy Hide Login, Vulnerability Report Leave a comment

Post navigation

Follow Us

  • Google News
  • Bluesky
  • RSS

Latest Plugin Security Reviews

  • WordPress Plugin Security Review: FV Gravatar Cache
  • WordPress Plugin Security Review: Popup Builder
  • WordPress Plugin Security Review: WP Time Capsule
Powered by WordPress and WooCommerce
© 2016-2025 White Fir Design LLC | Privacy Policy
Fruitful theme by fruitfulcode
↑