CVE-2024-6420
Hide My WP Ghost < 5.2.02 - Hidden Login Page Disclosure
Record summary
CVE-2024-6420 has a selected CVSS score of 8.6 (high); EIP currently links 1 Nuclei template.
Description
The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
Exploitation context
Available material
- Nuclei templates
- 1
CISA SSVC decision
CISA Coordinator · SSVC 2.0.3 · Evaluated Jul 29, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Hide My WP GhostDefault status: unaffected | CVE List | Before 5.2.02 | affected |
hide_my_wp_ghostBrowse wpplugins / hide_my_wp_ghostDefault status: unknown | CVE List | Before 5.2.02 | affected |
Nuclei templates
1ProjectDiscoveryHIGHHide My WP Ghost < 5.2.02 - Hidden Login Page DisclosureCVSS 8.6
The Hide My WP Ghost plugin does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
Impact
Unauthenticated attackers can discover and access the hidden WordPress login page through auth_redirect exploitation, bypassing the plugin's security obfuscation.
Remediation
Update Hide My WP Ghost plugin to version 5.2.02 or later to address the login page disclosure vulnerability.
Source: ProjectDiscovery