CVE-2024-13794

Severity CVSS v4.0:
Pending analysis
Type:
CWE-693 Protection Mechanism Failure
Publication date:
12/02/2025
Last modified:
25/02/2025

Description

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login page location.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:wpplugins:hide_my_wp_ghost:*:*:*:*:*:wordpress:*:* 5.4.01 (excluding)