CVE-2024-13794: Hide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page Disclosure
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login page location.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-13794?
CVE-2024-13794 is considered a medium severity vulnerability due to its potential for unauthorized access through login page disclosure.
How do I fix CVE-2024-13794?
To fix CVE-2024-13794, update the WP Ghost (Hide My WP Ghost) – Security & Firewall plugin to the latest version beyond 5.3.02.
What versions are affected by CVE-2024-13794?
CVE-2024-13794 affects all versions of the WP Ghost (Hide My WP Ghost) plugin up to and including version 5.3.02.
What kind of vulnerability is CVE-2024-13794?
CVE-2024-13794 is a login page disclosure vulnerability that allows unauthenticated attackers to access sensitive information.
Who is the vendor for CVE-2024-13794?
The vendor for CVE-2024-13794 is WP Ghost, which develops the Hide My WP Ghost – Security & Firewall plugin.