cve/2024/CVE-2024-6420.md
2024-08-11 18:44:53 +00:00

18 lines
775 B
Markdown

### [CVE-2024-6420](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-6420)
![](https://img.shields.io/static/v1?label=Product&message=Hide%20My%20WP%20Ghost%20&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=0%3C%205.2.02%20&color=brighgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-200%20Information%20Exposure&color=brighgreen)
### Description
The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
### POC
#### Reference
- https://wpscan.com/vulnerability/dfda6577-81aa-4397-a2d6-1d736f9ebd44/
#### Github
- https://github.com/20142995/nuclei-templates