CVE-2026-86796 PUBLISHED

WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters

Assigner: WPScan
Reserved: 08.09.2026 Published: 18.09.2026 Updated: 18.09.2026

The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS Score: 5.3

Product Status

Vendor Unknown
Product Hide My WP Ghost
Versions Default: unaffected
  • affected from 7.0.10 to 7.0.11 (excl.)

Credits

  • Kenny finder
  • WPScan coordinator

References

Problem Types

  • CWE-693 Protection Mechanism Failure CWE