PT-2026-95791 · WordPress · Wp Ghost
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress versions prior to 7.0.03
Description
An Open Redirect issue exists because the plugin fails to properly validate user input. Unauthenticated attackers can redirect users to malicious websites by tricking them into clicking a specially crafted link. The attack chain involves tricking a logged-in user into clicking a crafted logout URL, which triggers the
wp logout() function to fully log the victim out before the redirect occurs, making the logout irreversible.Recommendations
Update the plugin to a version newer than 7.0.02.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Ghost