Description
The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized disabling of security controls exposing hidden WordPress login and admin URLs
Action: Patch
AI Analysis

Impact

The Hide My WP Ghost WordPress plugin before 7.0.11 does not confirm that a request originates from a legitimate WooCommerce source before turning off its firewall, threat‑detection mechanisms, and URL‑hiding functionality. An attacker‑supplied request parameter is sufficient to trigger this action, allowing an unauthenticated user to disable those protections and re‑expose the concealed login and admin URLs.

Affected Systems

Any WordPress site that has the Hide My WP Ghost plugin installed with a version earlier than 7.0.11 is affected. The vulnerability applies to all releases up to, but excluding, 7.0.11, regardless of whether WooCommerce is present; a request parameter alone can trigger the bypass.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request that includes a WooCommerce‑style parameter; no credentials or administrative access are required to activate the bypass.

Generated by OpenCVE AI on September 19, 2026 at 20:42 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hide My WP Ghost to version 7.0.11 or later, which validates WooCommerce requests before disabling protections.
  • Disable or remove the hidden login/admin URL feature until the plugin update is confirmed.
  • Restrict incoming WooCommerce parameters in the website’s firewall or server configuration to prevent unauthorized toggling of security controls.

Generated by OpenCVE AI on September 19, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions wp Ghost
Vendors & Products Wordpress-extensions
Wordpress-extensions wp Ghost

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.
Title WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress-extensions Wp Ghost
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T10:59:56.068Z

Reserved: 2026-09-08T12:13:06.314Z

Link: CVE-2026-86796

cve-icon Vulnrichment

Updated: 2026-09-18T10:53:11.943Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:50.543

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-86796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:57Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure