What the vulnerability does
01Description
Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.
Explanation of Vulnerability in Simple Terms
02Summary
Hide My WP Ghost versions up to 5.0.25 contain a flaw that allows attackers to modify site data without authentication. The vulnerability requires only network access and no user interaction. Site administrators should update to a version newer than 5.0.25 to prevent unauthorized changes to their WordPress installation.
What an attacker can do
03Attacker Capabilities
Modify site data or content without logging in.
Potential impact on your site
04Site Impact
Attackers can alter your site's content, settings, or data without your knowledge or permission.
Conditions required to exploit
05Prerequisites
Network access only; no authentication or user interaction required.
Key dates
06Disclosure timeline
June 4, 2024
CVE published
April 28, 2026
Record updated