CVE-2026-86796: WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters
The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress plugin: Hide My WP Ghost (WP Ghost)to a version that resolves this vulnerability.Fixed in 7.0.11 - Compensating control
Until the plugin is updated, restrict public access to the site (e.g., via a WAF/ACL) to reduce the chance that unauthenticated attackers can reach endpoints where the attacker-suppliable WooCommerce request parameter is used to disable firewall, threat-detection, and login/URL-hiding protections.
Event History
Frequently Asked Questions
Which installations are affected?
Hide My WP Ghost versions before 7.0.11 are affected. The issue applies where the plugin’s firewall, threat-detection, or login/URL-hiding protections are relied upon.
Does exploitation require authentication or user interaction?
No. An unauthenticated attacker can exploit the issue remotely without user interaction by supplying the relevant WooCommerce request parameter.
What protections can be bypassed?
The attacker can cause the plugin to disable its firewall, threat-detection, and login/URL-hiding protections for a request. This can re-expose concealed login and administrative URLs.
What should be done if immediate patching is not possible?
The provided information does not identify a workaround. Treat concealed login and admin URLs as potentially exposed until the plugin is updated to version 7.0.11 or later.