Input validation vulnerability in Hide My WP Ghost – Security Plugin 5.0.25

The Hide My WP Ghost plugin for WordPress is vulnerable to a security issue. This means that people who aren’t supposed to be able to access the website may be able to do so. The issue affects versions of the plugin up to and including 5.0.25. It is caused by a mistake in the code of the “brute_math_authenticate” function, which allows unauthenticated attackers to bypass the CAPTCHA security measure by not including the “brute_ck” parameter in their authentication request.

Detected in:

Hide My WP Ghost – Security & Firewall fixed vulnerable versions:
Hide My WP Ghost – Security Plugin fixed vulnerable versions: >= * <= 5.0.25
WP Ghost – Security & Firewall fixed vulnerable versions:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.