### [CVE-2024-6420](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6420) ![](https://img.shields.io/static/v1?label=Product&message=Hide%20My%20WP%20Ghost%20&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=0%3C%205.2.02%20&color=brighgreen) ![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-200%20Information%20Exposure&color=brighgreen) ### Description The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page. ### POC #### Reference - https://wpscan.com/vulnerability/dfda6577-81aa-4397-a2d6-1d736f9ebd44/ #### Github No PoCs found on GitHub currently.