Impact
The Hide My WP Ghost plugin fails to validate a loopback security‑check request before deactivating its login and URL hiding features. An attacker can trigger this validation failure by sending a crafted request lacking the correct verification value, causing the plugin to relinquish its protection. The result is that the concealed WordPress login URL is publicly visible, exposing the site to credential‑guessing and brute‑force attacks. This weakness is identified as CWE‑693, improper validation.
Affected Systems
The plugin version before 7.0.11 from the Hide My WP Ghost project for WordPress is affected. No other vendors or product families are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity. The EPSS score of under 1 % suggests a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can trigger the bypass from any network location with site access, does not need authentication, and can expose the login page, enabling credential attacks that could lead to higher‑level compromise if weak credentials are used. This reflects an improper validation flaw (CWE‑693).
OpenCVE Enrichment