Record summary

CVE-2024-6420 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.

Description

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 29, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Hide My WP Ghost

Default status: unaffected

CVE ListBefore 5.2.02affected

Default status: unknown

CVE ListBefore 5.2.02affected

Nuclei templates

1
ProjectDiscoveryHIGHHide My WP Ghost < 5.2.02 - Hidden Login Page DisclosureCVSS 8.6

The Hide My WP Ghost plugin does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

Impact

Unauthenticated attackers can discover and access the hidden WordPress login page through auth_redirect exploitation, bypassing the plugin's security obfuscation.

Remediation

Update Hide My WP Ghost plugin to version 5.2.02 or later to address the login page disclosure vulnerability.

Authorsjpg0mez
Template tagscvecve2024bypasswpwp-pluginwpscanwordpresshide-my-wpvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
FOFA: body="/wp-content/plugins/hide-my-wp"

Source: ProjectDiscovery

References

2