CVE-2026-86800
WP Ghost (Hide My WP Ghost) < 7.0.11 - Unauthenticated URL Hiding Bypass via Loopback Compatibility Check
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing unauthenticated attackers to re-expose the concealed WordPress login page location.
| Vendor | unknown |
| Product | hide my wp ghost |
| Published | Sep 18, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown hide my wp ghost
Be the first to know when new medium vulnerabilities affecting unknown hide my wp ghost are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Unknown / Hide My WP Ghost
0 < 7.0.11
References
Credits
Animesh Gaurav WPScan