CVE-2023-34001
WordPress Hide My WP Ghost – Security Plugin plugin <= 5.0.25 - Captcha Bypass vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.
Vulnerabilidad de restricción inadecuada de intentos de autenticación excesivos en WPPlugins – WordPress Security Plugins Hide My WP Ghost permiten la omisión de funcionalidad. Este problema afecta a Hide My WP Ghost: desde n/a hasta 5.0.25.
The Hide My WP Ghost plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 5.0.25. This is due a logic flaw within the brute_math_authenticate function. This makes it possible for unauthenticated attackers to bypass CAPTCHA by omitting the `brute_ck` parameter from the authentication request.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-05-25 CVE Reserved
- 2023-08-22 CVE Published
- 2024-06-04 EPSS Updated
- 2024-08-02 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-307: Improper Restriction of Excessive Authentication Attempts
- CWE-807: Reliance on Untrusted Inputs in a Security Decision
CAPEC
- CAPEC-554: Functionality Bypass
References (1)
URL | Tag | Source |
---|---|---|
https://patchstack.com/database/vulnerability/hide-my-wp/wordpress-hide-my-wp-ghost-security-plugin-plugin-5-0-24-captcha-bypass-vulnerability?_s_id=cve | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Hide My Wp Search vendor "Hide My Wp" | Hide My Wp Search vendor "Hide My Wp" for product "Hide My Wp" | >= 0.0.0 <= 5.0.25 Search vendor "Hide My Wp" for product "Hide My Wp" and version " >= 0.0.0 <= 5.0.25" | en |
Affected
|