.. / CVE-2022-1595

Exploit for WordPress HC Custom WP-Admin URL <=1.4 - Admin Login URL Disclosure (CVE-2022-1595)

Description:

WordPress HC Custom WP-Admin URL plugin through 1.4 leaks the secret login URL when sending a specially crafted request, thereby allowing an attacker to discover the administrative login URL.

Nuclei Template

View the template here CVE-2022-1595.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2022/CVE-2022-1595.yaml
Copy

References:

https://wordpress.org/plugins/hc-custom-wp-admin-url/
https://nvd.nist.gov/vuln/detail/CVE-2022-1595
https://wpscan.com/vulnerability/0218c90c-8f79-4f37-9a6f-60cf2f47d47b