Correct, and the only way to fix it (as you simply can’t login afterwards) is to manually go into the database and turn the option off in the json string :\
Hi, sorry.
I took a screenshot, here: http://postimg.org/image/oheconnt5/
When I use this feature, the wp-admin gives a soft 404 (as expected), but the url I put in to become the new login url gives me a hard 404 i.e., an apache 404 error. I looked into .htaccess but think this is done at php level using headers and don’t really have time to debug this properly.
Point is, this works fine when not using WP from within a folder as I am using aio wp security on other sites without issue 🙂
Hope this helps!
Hakun