CVE-2023-34001
The Hide My WP Ghost security plugin for WordPress versions 5.0.25 and earlier contains a logic error in the brute_math_authenticate function that allows unauthenticated users to circumvent CAPTCHA protection. An attacker can bypass the CAPTCHA mechanism by simply not including the `brute_ck` parameter when submitting an authentication request. This flaw exposes the authentication process to brute force attacks since the CAPTCHA verification can be skipped entirely. Updating to version 5.0.26 or later resolves this vulnerability.
Based on public CVE data (MITRE/NVD).