CVE-2024-6420: Wpplugins Hide My Wp Ghost

High severity, CVSS 8.6. EPSS: 1.8% chance of exploitation in the next 30 days.

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

Affected products

  • Wpplugins Hide My Wp Ghost: before 5.2.02 (fixed in 5.2.02)

Published 2024-07-23. Last modified 2026-06-17.