Correct : by-move security issue allowing an unauthenticated person to receive login website page by environment a random referer string by way of curl ask for. This situation can originate from plugins modifying your .htaccess files to include or change policies, or from an old WordPress MU configuration not up https://telescope.ac/b006c3b8/nff9w4sg5ctym1hrfe5wr3