Description
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validating user input. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into clicking on a specially crafted link. Exploitation requires tricking a logged-in user into clicking a crafted logout URL; the victim is fully logged out via wp_logout() before the malicious redirect is issued, making the logout irreversible as part of the attack chain.
Published: 2026-09-19
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect
Action: Upgrade Plugin
AI Analysis

Impact

The Hide My WP Ghost – Security & Firewall plugin allows an unauthenticated attacker to redirect users to an arbitrary external URL by using an unvalidated parameter named redirect_to. The flaw, classified as CWE-601, permits an attacker to craft a link that logs the victim out via wp_logout() and then forwards them to a malicious site. This opens the door to phishing or malware delivery once a user clicks the link.

Affected Systems

Any WordPress installation that has the Hide My WP Ghost – Security & Firewall plugin version 7.0.02 or earlier is affected. The vulnerability is confined to the plugin code; it does not depend on the hosting operating system or additional components.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity, while the EPSS score of less than 1 % suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to be tricked into clicking a specially crafted logout URL that contains the invalid redirect_to value. No authentication or elevated privileges are needed, and the success rate depends on social engineering.

Generated by OpenCVE AI on September 19, 2026 at 23:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hide My WP Ghost to the latest version available from the plugin author, checking the update log for a fix to redirect validation.
  • If an immediate upgrade is not possible, disable the redirect functionality in the plugin – remove the redirect_to handling in the code or, if the plugin offers a configuration option, turn off external redirects.
  • Deploy a content‑security‑policy header that restricts navigation to approved domains, thereby limiting the impact of any remaining redirect.

Generated by OpenCVE AI on September 19, 2026 at 23:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Johndarrel
Johndarrel hide My Wp Ghost – Security & Firewall
Wordpress
Wordpress wordpress
Vendors & Products Johndarrel
Johndarrel hide My Wp Ghost – Security & Firewall
Wordpress
Wordpress wordpress

Sat, 19 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 19 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validating user input. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into clicking on a specially crafted link. Exploitation requires tricking a logged-in user into clicking a crafted logout URL; the victim is fully logged out via wp_logout() before the malicious redirect is issued, making the logout irreversible as part of the attack chain.
Title WP Ghost (Hide My WP Ghost) <= 7.0.02 - Unauthenticated Open Redirect via 'redirect_to' Parameter
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N'}


Subscriptions

Johndarrel Hide My Wp Ghost – Security & Firewall
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-09-19T14:01:21.774Z

Reserved: 2026-04-30T17:29:33.893Z

Link: CVE-2026-7527

cve-icon Vulnrichment

Updated: 2026-09-19T13:51:17.574Z

cve-icon NVD

Status : Deferred

Published: 2026-09-19T08:16:54.623

Modified: 2026-09-21T13:33:33.387

Link: CVE-2026-7527

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-21T10:03:21Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')