PT-2026-95259 · WordPress · Hide My Wp Ghost
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hide My WP Ghost versions prior to 7.0.11
Description
The plugin fails to verify if a request is a genuine WooCommerce request before disabling its firewall, threat-detection, and login/URL-hiding protections. An unauthenticated attacker can trigger this by providing a specific request parameter, which disables these security features and re-exposes the concealed login and admin URLs on any request.
Recommendations
Update Hide My WP Ghost to version 7.0.11 or later.
Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hide My Wp Ghost