WPS-Hide-Login plugin before 1.5.3 for WordPress contains an action=confirmaction protection bypass, letting attackers bypass security checks, exploit requires sending crafted requests.
id: CVE-2019-15823
info:
name: WPS Hide Login <= 1.5.2.2 - Login Page Bypass
author: pussycat0
...