No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 18 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-693 | |
| Metrics |
ssvc
|
Fri, 18 Sep 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request. | |
| Title | WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2026-09-18T10:59:56.068Z
Reserved: 2026-09-08T12:13:06.314Z
Link: CVE-2026-86796
Updated: 2026-09-18T10:53:11.943Z
Status : Deferred
Published: 2026-09-18T07:16:50.543
Modified: 2026-09-18T19:08:32.830
Link: CVE-2026-86796
No data.
OpenCVE Enrichment
No data.
-
CWE-693
Protection Mechanism Failure