The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login page location.
References
Configurations
History
No history.
Information
Published : 2025-02-12 08:15
Updated : 2025-02-25 19:38
NVD link : CVE-2024-13794
Mitre link : CVE-2024-13794
CVE.ORG link : CVE-2024-13794
JSON object : View
Products Affected
wpplugins
- hide_my_wp_ghost
CWE
