PT-2024-37613 · WordPress · Hide My Wp Ghost

Jpgp

+1

·

Published

2024-07-23

·

Updated

2024-08-01

·

CVE-2024-6420

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions Hide My WP Ghost WordPress plugin versions prior to 5.2.02
Description The issue allows an unauthenticated visitor to access the hidden login page due to the plugin not preventing redirects to the login page via the auth redirect WordPress function.
Recommendations For versions prior to 5.2.02, update to version 5.2.02 or later to resolve the issue. As a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation.

Exploit

Fix

Related Identifiers

CVE-2024-6420

Affected Products

Hide My Wp Ghost