Hide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page Disclosure

Strategic Overview

Status
Patched in 5.4.01
Affected Version<= 5.3.02
CVSS5.3Medium
CVECVE-2024-13794
View all WP Ghost (Hide My WP Ghost) – Security & Firewall vulnerabilities

Vulnerability Overview

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login page location.

Technical Analysis

REMEDIATION: Update to version 5.4.01, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

External References

Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C