CVE Database /
CVE-2024-13794
CVE · Medium
CVE-2024-13794 — WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.01
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2024-13794
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.01 |
Protection Mechanism Failure |
Medium
5.3
|
< 5.4.01
|
5.4.01 |
2025-02-11 |
—
|
CVE-2024-13794
The Hide My WP Ghost plugin for WordPress contains a login page disclosure vulnerability affecting versions up to and including 5.3.02. The flaw exists because the plugin fails to adequately restrict access to the /wp-register.php path, allowing unauthenticated users to determine the location of the concealed login page. This weakness undermines the plugin's core security purpose of hiding WordPress administration interfaces from unauthorized access.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings