CVE-2023-5089Disclosure(wpmudev / defender_security)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled.

1.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • defender_security

Threat summary

  • Public PoC is present in monitored signal
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Exploit: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-09-17)
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
defender_security

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-03-16: 1Mentions · 2026-08-27: 1Mentions · 2026-09-17: 2PoC Mentioned / Linked · 2026-08-27: 1Technical Details · 2026-03-16: 1Technical Details · 2026-08-27: 1Technical Details · 2026-09-17: 203-1608-2709-17
Signal classification3 categories
Disclosure
250.0%
Exploit
125.0%
PoC
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-161
Exploit1
2026-08-271
PoC1
2026-09-172
Disclosure2
Full discourse4 posts
  • Daily Bug Bounty Reports@Bug_Breakdown
    Disclosure

    Bypassing a 403 Forbidden on a NASA admin panel to expose a hidden WordPress login. When a target blocks you at the front door, use their own redirect logic to walk in through the back. Bug: Hidden Login & 403 Bypass via auth_redirect (CVE-2023-5089) The Flaw: Security plugins designed to hide WordPress login pages (like Defender Security < 4.1.0) fail to properly enforce access restrictions when handling native auth_redirect requests. The Exploit: By forcing a redirect to the protected NASA endpoint using unauthenticated parameters (e.g., ?gf_page=randomstring), you hit the initial 403 block. From there, manipulating the URL path with ?redirect_to= and &reauth=1 completely drops the 403 restriction and exposes the hidden admin panel. Methodology Tip: When a WAF or plugin drops a 403 on an authentication endpoint, don't walk away. Hunt for unauthenticated features that force an internal redirection to that protected resource. If you can control the redirection state, you can often break the access control logic. Read exactly how this was chained on the live NASA target in the replies 👇 #BugBounty #AppSec #WordPress #CyberSecurity #BugBountyReports #BugBountyTips #InfoSec

    Post summary

    The text discloses CVE-2023-5089, a hidden login and 403 bypass flaw in WordPress security plugins (e.g., Defender Security <4.1.0) exploitable via auth_redirect manipulation, providing technical details but no mention of patches, PoC, or active exploitation.

    10010220
    57 followersView on X
  • Daily Bug Bounty Reports@Bug_Breakdown
    Disclosure

    https://infosecwriteups.com/nasa-hidden-login-page-bypass-via-auth-redirect-403-bypass-cve-2023-5089-2999fa3ca4d4

    Post summary

    The text is a URL referencing a writeup about CVE-2023-5089, disclosing technical details regarding an authentication redirect and 403 bypass vulnerability, but lacking information on active exploitation, specific exploit tools, or available patches.

    00000106
    57 followersView on X
  • Miguel Méndez Zúñiga@s1kr10s
    PoC

    @NASA Hidden Login Page Bypass A write-up covering an interesting auth redirect / 403 bypass involving a hidden login page and CVE-2023-5089. write-up: https://medium.com/bugbountywriteup/nasa-hidden-login-page-bypass-via-auth-redirect-403-bypass-cve-2023-5089-2999fa3ca4d4

    Post summary

    A Medium article details an auth‑redirect/403 bypass for CVE‑2023‑5089, providing a proof of concept but offering no evidence of active exploitation or patch guidance.

    0000047
    1.3K followersView on X
  • Miguel Méndez Zúñiga@s1kr10s
    Exploit

    🚨 @NASA Login discovered!
Defender Security (&lt;4.1.0) allows bypassing hidden login pages.
By abusing auth_redirect (CVE-2023-5089) + URL path manipulation, HTTP 403 can be bypassed. #CyberSecurity #BugBounty #EthicalHacking #Infosec https://youtu.be/yIx0XLx-iRQ

    Post summary

    The post reports an authentication bypass in Defender Security (<4.1.0) via auth_redirect abuse and URL path manipulation, allowing attackers to circumvent HTTP 403, but it provides no code, patch, or evidence of in‑the‑wild exploitation.

    00000192
    1.3K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwpmudevdefender_security-wordpress-

Explore more