{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/rename-wp-login.php-to-anything-you-want--2.0.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:rename_wp-login.php_to_anything_you_want_project:rename_wp-login.php_to_anything_you_want:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93368"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Rename wp-login.php to anything you want (\u003c= 2.0.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe 'Rename wp-login.php to anything you want' plugin for WordPress (all versions up to and including 2.0.1) contains a critical security vulnerability identified as CVE-2026-93368. The vulnerability is a time-based SQL injection occurring within the 'log' (username) parameter. The flaw stems from insufficient input sanitization and the application of WordPress core 'wp_unslash()' function on user-supplied data before it reaches the plugin's handler. By stripping backslash escaping, this function allows raw single quotes to reach the database query unimpeded. Unauthenticated attackers can leverage this to append malicious SQL queries to existing ones, potentially leading to unauthorized data exfiltration from the WordPress database. Given that the 'log' parameter is processed during login attempts, this provides an accessible vector for attackers to perform blind SQL injection attacks by measuring database response times.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to perform SQL injection against the underlying database. This could result in unauthorized access to sensitive information stored in the WordPress database, including user credentials, configuration data, and site content. Since the vulnerability does not require administrative privileges, any internet-facing WordPress site running this plugin version is at risk of information disclosure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eImmediate action is required for all WordPress installations utilizing the 'Rename wp-login.php to anything you want' plugin.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the plugin to the latest version (patch for CVE-2026-93368) as soon as it is released by the developer.\u003c/li\u003e\n\u003cli\u003eIf an update is unavailable, deactivate and uninstall the plugin to eliminate the vulnerable code path.\u003c/li\u003e\n\u003cli\u003eImplement Web Application Firewall (WAF) rules to inspect the 'log' parameter for common SQL injection characters (such as single quotes and sleep/benchmark functions) specifically targeting requests to the plugin's custom login endpoint.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to the login page containing SQL injection patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-23T10:42:51Z","date_published":"2026-09-23T10:42:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wordpress-sqli/","summary":"The 'Rename wp-login.php to anything you want' WordPress plugin is vulnerable to unauthenticated time-based SQL injection via the 'log' parameter, allowing sensitive database information extraction.","title":"SQL Injection in Rename wp-login.php WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wordpress-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Rename Wp-Login.php to Anything You Want (\u003c= 2.0.1)","version":"https://jsonfeed.org/version/1.1"}