#VU19361 Information disclosure in WPS Hide Login
Published: July 25, 2019
WPS Hide Login
Rémy Perona
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists in the "/classes/plugin.php" file due to the function "wpmu_activate_signup()" is not declared yet. A remote attacker can trigger the hook “wps_hide_login_signup_enable” with the correct URL and disclose the path information on the system.