cve/2024/CVE-2024-6420.md
2024-08-11 18:44:53 +00:00

775 B

CVE-2024-6420

Description

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

POC

Reference

Github