Rename wp-login.php to anything you want <= 2.0.1 - Unauthenticated SQL Injection via 'log' (Username) Parameter (CVE-2026-93368) | HOL Guard CVE