CVE-2024-6420: Wpplugins Hide My Wp Ghost
High severity, CVSS 8.6. EPSS: 1.8% chance of exploitation in the next 30 days.
The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.
Affected products
- Wpplugins Hide My Wp Ghost: before 5.2.02 (fixed in 5.2.02)
Published 2024-07-23. Last modified 2026-06-17.