Hide My WP Ghost <= 5.0.25 - CAPTCHA Bypass in brute_math_authenticate
2023-08-22 00:00
konagashStrategic Overview
StatusPatched in 5.0.26
Affected PluginWP Ghost (Hide My WP Ghost) – Security & Firewall
Affected Version
<= 5.0.25CVSS5.3Medium
CVE
CVE-2023-34001Vulnerability Overview
The Hide My WP Ghost plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 5.0.25. This is due a logic flaw within the brute_math_authenticate function. This makes it possible for unauthenticated attackers to bypass CAPTCHA by omitting the `brute_ck` parameter from the authentication request.
Technical Analysis
REMEDIATION: Update to version 5.0.26, or a newer patched version --- IDENTIFIER: CWE-807 (Reliance on Untrusted Inputs in a Security Decision) The product uses a protection mechanism that relies on the existence or values of an input, but the input can be modified by an untrusted actor in a way that bypasses the protection mechanism.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C