CVE-2023-34001: WordPress Hide My WP Ghost – Security Plugin plugin <= 5.0.25 - Captcha Bypass vulnerability
Published Jun 4, 2024
·Updated
Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.
Affected Software
3 affected components
WPPlugins Hide My WP Ghost<=5.0.25
WordPress Hide My WP Ghost<=5.0.25
WPPlugins Hide My Wp Ghost Wordpress<5.0.26
Remediation
Information
Update to 5.0.26 or a higher version.
Event History
Jun 4, 2024
CVE Published
via MITRE·07:09 AM
Data Sourced
via MITRE·07:09 AM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2023-34001?
CVE-2023-34001 has a high severity rating due to its potential to bypass authentication mechanisms.
2
How do I fix CVE-2023-34001?
To fix CVE-2023-34001, upgrade to Hide My WP Ghost version 5.0.26 or later.
3
What type of vulnerability is CVE-2023-34001?
CVE-2023-34001 is an improper restriction of excessive authentication attempts vulnerability.
4
Which versions of Hide My WP Ghost are affected by CVE-2023-34001?
CVE-2023-34001 affects Hide My WP Ghost versions up to and including 5.0.25.
5
What functionality does CVE-2023-34001 allow attackers to bypass?
CVE-2023-34001 allows attackers to bypass volume-based authentication restrictions, potentially leading to unauthorized access.