CVE-2022-1595 describes a vulnerability in the HC Custom WP-Admin URL WordPress plugin, versions up to and including 1.4, where a crafted request can lead to the disclosure of the secret login URL. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low-complexity attack that can be executed remotely without authentication, resulting in a partial confidentiality impact. While not currently listed on the CISA KEV catalog or Hot List, Nuclei templates exist for detecting this vulnerability, suggesting readily available exploit code. Despite this, there is no evidence of active exploitation, and community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.4CPE matchmatch criteria | cpe:2.3:a:hc_custom_wp-admin_url_project:hc_custom_wp-admin_url:*:*:*:*:*:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.