Custom Login URL vulnerability

Hi,

Curiously, once a secret login URL is set in Classic Monks > Custom Login URL, accessing most of the WP login page URLs redirects to a 404 or a specific page:

/wp-login.php
/wp-admin
/admin

And accessing one of them redirects to… the secret URL, which undermines the very purpose of the function:

/login

Is it just me?

I checked the same feature in Perfmatters, /login is filtered alright as the others.

1 Like

Hi @avanti
Thanks for catching and reporting this bug, it has been identified and fixed.
New updated 1.1.7 coming up in next few hours.