Impact
The vulnerability is a broken authentication flaw in the Hide My WP Ghost plugin versions up to 7.0.06. A malicious actor can bypass the two‑factor authentication required for authentication, allowing them to impersonate legitimate users or elevate privileges when accessing the WordPress site. This results in a loss of confidentiality and integrity of site content and potentially full control of the site.
Affected Systems
This issue affects installations of the Hide My WP Ghost plugin for WordPress whose version is 7.0.06 or earlier. The plugin is maintained by John Darrel and is widely used to obscure site URLs and other content. Any WordPress site that has the plugin installed and is running a vulnerable version is susceptible.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity; the problem is likely exploitable over the network since it involves bypassing authentication on a publicly accessible WordPress site. Although the EPSS score is < 1%, the low probability of exploitation does not diminish the potential risk. Attackers could exploit this from any IP address that can reach the site, and the impact would be full administrative takeover if the account they bypassed has high privileges. Administrators should therefore treat this as a high‑risk issue.
OpenCVE Enrichment