The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login page location.
References
Configurations
History
25 Feb 2025, 19:38
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:wpplugins:hide_my_wp_ghost:*:*:*:*:*:wordpress:*:* | |
References | () https://plugins.trac.wordpress.org/changeset?sfp_email=&sfph_mail=&reponame=&old=3235271%40hide-my-wp&new=3235271%40hide-my-wp&sfp_email=&sfph_mail= - Patch | |
References | () https://www.wordfence.com/threat-intel/vulnerabilities/id/9effa526-7454-4490-9bf4-0605254d6625?source=cve - Third Party Advisory | |
CWE | NVD-CWE-noinfo | |
First Time |
Wpplugins
Wpplugins hide My Wp Ghost |
18 Feb 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
12 Feb 2025, 08:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-02-12 08:15
Updated : 2025-02-25 19:38
NVD link : CVE-2024-13794
Mitre link : CVE-2024-13794
CVE.ORG link : CVE-2024-13794
JSON object : View
Products Affected
wpplugins
- hide_my_wp_ghost
CWE