CVE-2024-6420

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpplugins:hide_my_wp_ghost:*:*:*:*:*:wordpress:*:*

History

17 Jun 2026, 08:17

Type Values Removed Values Added
Summary (en) The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page. (en) The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

29 May 2025, 16:08

Type Values Removed Values Added
CPE cpe:2.3:a:wpplugins:hide_my_wp_ghost:*:*:*:*:*:wordpress:*:*
First Time Wpplugins hide My Wp Ghost
Wpplugins
References () https://wpscan.com/vulnerability/dfda6577-81aa-4397-a2d6-1d736f9ebd44/ - () https://wpscan.com/vulnerability/dfda6577-81aa-4397-a2d6-1d736f9ebd44/ - Exploit, Third Party Advisory
CWE NVD-CWE-noinfo

21 Nov 2024, 09:49

Type Values Removed Values Added
References () https://wpscan.com/vulnerability/dfda6577-81aa-4397-a2d6-1d736f9ebd44/ - () https://wpscan.com/vulnerability/dfda6577-81aa-4397-a2d6-1d736f9ebd44/ -

01 Aug 2024, 14:00

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.6

24 Jul 2024, 12:55

Type Values Removed Values Added
Summary
  • (es) El complemento de WordPress Hide My WP Ghost anterior a 5.2.02 no impide las redirecciones a la página de inicio de sesión a través de la función auth_redirect de WordPress, lo que permite que un visitante no autenticado acceda a la página de inicio de sesión oculta.

23 Jul 2024, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-07-23 06:15

Updated : 2026-06-17 08:17


NVD link : CVE-2024-6420

Mitre link : CVE-2024-6420

CVE.ORG link : CVE-2024-6420


JSON object : View

Products Affected

wpplugins

  • hide_my_wp_ghost