CVE-2026-81806: WordPress Hide My WP Ghost plugin <= 7.0.09 - Server Side Request Forgery (SSRF) vulnerability
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery.
This issue affects Hide My WP Ghost: from n/a through 7.0.09.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Hide My WP Ghost Pluginto a version that resolves this vulnerability.Fixed in 7.0.10
Event History
Frequently Asked Questions
Which deployments are affected?
Hide My WP Ghost versions through 7.0.09 are affected. The available information does not identify any configuration prerequisite or indicate that a non-default setup is required.
Does exploitation require an authenticated WordPress user or user interaction?
No. The supplied CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction.
What security impact is indicated?
The CVSS vector indicates low confidentiality and integrity impact, no availability impact, and scope change. The vulnerability is classified as server-side request forgery.