Description
Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
Published: 2026-07-27
Score: 7.4 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a broken authentication flaw in the Hide My WP Ghost plugin versions up to 7.0.06. A malicious actor can bypass the two‑factor authentication required for authentication, allowing them to impersonate legitimate users or elevate privileges when accessing the WordPress site. This results in a loss of confidentiality and integrity of site content and potentially full control of the site.

Affected Systems

This issue affects installations of the Hide My WP Ghost plugin for WordPress whose version is 7.0.06 or earlier. The plugin is maintained by John Darrel and is widely used to obscure site URLs and other content. Any WordPress site that has the plugin installed and is running a vulnerable version is susceptible.

Risk and Exploitability

The CVSS score of 7.4 indicates high severity; the problem is likely exploitable over the network since it involves bypassing authentication on a publicly accessible WordPress site. Although the EPSS score is < 1%, the low probability of exploitation does not diminish the potential risk. Attackers could exploit this from any IP address that can reach the site, and the impact would be full administrative takeover if the account they bypassed has high privileges. Administrators should therefore treat this as a high‑risk issue.

Generated by OpenCVE AI on August 3, 2026 at 17:36 UTC.

Remediation

Vendor Solution

Update the WordPress Hide My WP Ghost Plugin to the latest available version (at least 7.0.07).


OpenCVE Recommended Actions

  • Upgrade the Hide My WP Ghost plugin to version 7.0.07 or later.
  • If upgrading is not immediately possible, temporarily disable the plugin to eliminate the attack vector.
  • Audit user accounts to ensure only authorized users have administrator privileges and reinforce two‑factor authentication on those accounts.
  • Monitor authentication logs for suspicious activity and set up alerts for unauthorized login attempts.

Generated by OpenCVE AI on August 3, 2026 at 17:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared John Darrel
John Darrel hide My Wp Ghost
Wordpress
Wordpress wordpress
Vendors & Products John Darrel
John Darrel hide My Wp Ghost
Wordpress
Wordpress wordpress

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.
Title WordPress Hide My WP Ghost plugin <= 7.0.06 - 2FA Bypass vulnerability
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

John Darrel Hide My Wp Ghost
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-27T16:09:14.102Z

Reserved: 2026-07-05T21:27:56.024Z

Link: CVE-2026-59546

cve-icon Vulnrichment

Updated: 2026-07-27T16:09:09.140Z

cve-icon NVD

Status : Deferred

Published: 2026-07-27T15:17:04.710

Modified: 2026-07-27T17:46:02.447

Link: CVE-2026-59546

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T17:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key