Impact
The Hide My WP Ghost WordPress plugin before 7.0.11 does not confirm that a request originates from a legitimate WooCommerce source before turning off its firewall, threat‑detection mechanisms, and URL‑hiding functionality. An attacker‑supplied request parameter is sufficient to trigger this action, allowing an unauthenticated user to disable those protections and re‑expose the concealed login and admin URLs.
Affected Systems
Any WordPress site that has the Hide My WP Ghost plugin installed with a version earlier than 7.0.11 is affected. The vulnerability applies to all releases up to, but excluding, 7.0.11, regardless of whether WooCommerce is present; a request parameter alone can trigger the bypass.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is less than 1%, suggesting a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request that includes a WooCommerce‑style parameter; no credentials or administrative access are required to activate the bypass.
OpenCVE Enrichment