Hide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page Disclosure
2025-02-11 00:00
Nicholas Mun (NRockhouse)Strategic Overview
StatusPatched in 5.4.01
Affected PluginWP Ghost (Hide My WP Ghost) – Security & Firewall
Affected Version
<= 5.3.02CVSS5.3Medium
CVE
CVE-2024-13794Vulnerability Overview
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login page location.
Technical Analysis
REMEDIATION: Update to version 5.4.01, or a newer patched version --- IDENTIFIER: CWE-693 (Protection Mechanism Failure) The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
External References
Vulnerability data © Defiant, Inc., provided under the Wordfence Intelligence T&C