CVE-2026-86796: WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters

Published Sep 18, 2026
·
Updated

The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.

Affected Software

1 affected component
WordPress plugin Hide My WP Ghost<7.0.11

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade WordPress plugin: Hide My WP Ghost (WP Ghost) to a version that resolves this vulnerability.

    Fixed in 7.0.11
  2. Compensating control

    Until the plugin is updated, restrict public access to the site (e.g., via a WAF/ACL) to reduce the chance that unauthenticated attackers can reach endpoints where the attacker-suppliable WooCommerce request parameter is used to disable firewall, threat-detection, and login/URL-hiding protections.

Event History

Sep 18, 2026
CVE Published
via MITRE·06:11 AM
Data Sourced
via MITRE·06:11 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which installations are affected?

Hide My WP Ghost versions before 7.0.11 are affected. The issue applies where the plugin’s firewall, threat-detection, or login/URL-hiding protections are relied upon.

2

Does exploitation require authentication or user interaction?

No. An unauthenticated attacker can exploit the issue remotely without user interaction by supplying the relevant WooCommerce request parameter.

3

What protections can be bypassed?

The attacker can cause the plugin to disable its firewall, threat-detection, and login/URL-hiding protections for a request. This can re-expose concealed login and administrative URLs.

4

What should be done if immediate patching is not possible?

The provided information does not identify a workaround. Treat concealed login and admin URLs as potentially exposed until the plugin is updated to version 7.0.11 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203