CVE · Medium

CVE-2024-13794 — WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.01

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2024-13794 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.01 Protection Mechanism Failure Medium 5.3 < 5.4.01 5.4.01 2025-02-11

CVE-2024-13794

The Hide My WP Ghost plugin for WordPress contains a login page disclosure vulnerability affecting versions up to and including 5.3.02. The flaw exists because the plugin fails to adequately restrict access to the /wp-register.php path, allowing unauthenticated users to determine the location of the concealed login page. This weakness undermines the plugin's core security purpose of hiding WordPress administration interfaces from unauthorized access.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.