CVE · Medium

CVE-2023-34001 — WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.26

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2023-34001 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.26 Improper Restriction of Excessive Authentication Attempts Medium 5.3 < 5.0.26 5.0.26 2023-08-22

CVE-2023-34001

The Hide My WP Ghost security plugin for WordPress versions 5.0.25 and earlier contains a logic error in the brute_math_authenticate function that allows unauthenticated users to circumvent CAPTCHA protection. An attacker can bypass the CAPTCHA mechanism by simply not including the `brute_ck` parameter when submitting an authentication request. This flaw exposes the authentication process to brute force attacks since the CAPTCHA verification can be skipped entirely. Updating to version 5.0.26 or later resolves this vulnerability.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.