Product
The 'Rename wp-login.php to anything you want' WordPress plugin is vulnerable to unauthenticated time-based SQL injection via the 'log' parameter, allowing sensitive database information extraction.