๐Ÿ” CVE Alert

CVE-2026-86796

MEDIUM 5.3

WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.

Vendor unknown
Product hide my wp ghost
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for unknown hide my wp ghost

Be the first to know when new medium vulnerabilities affecting unknown hide my wp ghost are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / Hide My WP Ghost
7.0.10 < 7.0.11

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/38baa866-c8a3-4c92-b7c8-8485e7c2a9b0/

Credits

Kenny WPScan