Description
The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing unauthenticated attackers to re-expose the concealed WordPress login page location.
Published: 2026-09-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Exposure of WordPress login page
Action: Apply Patch
AI Analysis

Impact

The Hide My WP Ghost plugin fails to validate a loopback security‑check request before deactivating its login and URL hiding features. An attacker can trigger this validation failure by sending a crafted request lacking the correct verification value, causing the plugin to relinquish its protection. The result is that the concealed WordPress login URL is publicly visible, exposing the site to credential‑guessing and brute‑force attacks. This weakness is identified as CWE‑693, improper validation.

Affected Systems

The plugin version before 7.0.11 from the Hide My WP Ghost project for WordPress is affected. No other vendors or product families are listed.

Risk and Exploitability

The CVSS score of 5.3 indicates a medium severity. The EPSS score of under 1 % suggests a low probability of current exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker can trigger the bypass from any network location with site access, does not need authentication, and can expose the login page, enabling credential attacks that could lead to higher‑level compromise if weak credentials are used. This reflects an improper validation flaw (CWE‑693).

Generated by OpenCVE AI on September 19, 2026 at 21:31 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Hide My WP Ghost plugin to version 7.0.11 or later.
  • Disable the plugin until the upgrade is performed if immediate patching is not possible.
  • Restrict access to the login page by IP address filtering or basic authentication until the plugin is updated.

Generated by OpenCVE AI on September 19, 2026 at 21:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions wp Ghost
Vendors & Products Wordpress-extensions
Wordpress-extensions wp Ghost

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Description The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing unauthenticated attackers to re-expose the concealed WordPress login page location.
Title WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility Check
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}


Subscriptions

Wordpress-extensions Wp Ghost
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-18T10:59:55.898Z

Reserved: 2026-09-08T12:19:54.151Z

Link: CVE-2026-86800

cve-icon Vulnrichment

Updated: 2026-09-18T10:53:09.679Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T07:16:50.670

Modified: 2026-09-18T19:08:32.830

Link: CVE-2026-86800

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T19:49:54Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure