WP Ghost (Hide My WP Ghost) – Security & Firewall < 7.0.05 - IP Spoofing to Protection Mechanism Bypass
medium
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to IP Spoofing in all versions up to 7.0.05 (exclusive). This makes it possible for unauthenticated attackers to bypass IP based protections.
- CVSS:
- 5.3
- Affected:
- up to 7.0.05
- Fixed in:
- 7.0.05
- Disclosed:
- Aug 4, 2026
CVE-2026-11870 on NVD →
WP Ghost (Hide My WP Ghost) – Security & Firewall <= 7.0.06 - Two-Factor Authentication Bypass
medium
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Two-Factor Authentication Bypass in all versions up to, and including, 7.0.06. This makes it possible for authenticated attackers, with Subscriber-level access and above, to bypass 2FA.
- CVSS:
- 4.3
- Affected:
- up to 7.0.06
- Fixed in:
- 7.0.07
- Disclosed:
- Jul 23, 2026
CVE-2026-59546 on NVD →
Hide My WP Ghost < 7.0.00 - Unauthenticated Open Redirect
medium
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to 7.0.00 (exclusive). This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can...
- CVSS:
- 4.7
- Affected:
- up to 7.0.00
- Fixed in:
- 7.0.00
- Disclosed:
- Mar 18, 2026
CVE-2026-39484 on NVD →
Hide My WP Ghost <= 5.4.01 - Unauthenticated Local File Inclusion
critical
The Hide My WP Ghost plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.01. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access co...
- CVSS:
- 9.8
- Affected:
- up to 5.4.01
- Fixed in:
- 5.4.02
- Disclosed:
- Mar 19, 2025
CVE-2025-26909 on NVD →
WP Ghost <= 5.4.01 - Unauthenticated Limited File Read
high
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it possible for unauthenticated attackers to read the contents of specific file types on the server, which can contain sensitive i...
- CVSS:
- 7.5
- Affected:
- up to 5.4.01
- Fixed in:
- 5.4.02
- Disclosed:
- Mar 13, 2025
CVE-2025-2056 on NVD →
Hide My WP Ghost – Security & Firewall <= 5.3.02 - Unauthenticated Login Page Disclosure
medium
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login...
- CVSS:
- 5.3
- Affected:
- up to 5.3.02
- Fixed in:
- 5.4.01
- Disclosed:
- Feb 11, 2025
CVE-2024-13794 on NVD →
Hide My WP Ghost – Security & Firewall <= 5.3.01 - Reflected Cross-Site Scripting via URL
medium
The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pag...
- CVSS:
- 6.1
- Affected:
- up to 5.3.01
- Fixed in:
- 5.3.02
- Disclosed:
- Nov 14, 2024
CVE-2024-10825 on NVD →
Hide My WP Ghost – Security & Firewall <= 5.2.01 - Login Page Disclosure
medium
The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 5.2.01. This is due to the plugin not prevent redirects to the login page when gravity forms is installed. This makes it possible for unauthenticated attackers to find the login p...
- CVSS:
- 5.3
- Affected:
- up to 5.2.01
- Fixed in:
- 5.2.02
- Disclosed:
- Jul 2, 2024
CVE-2024-6420 on NVD →
Hide My WP Ghost <= 5.0.25 - CAPTCHA Bypass in brute_math_authenticate
medium
The Hide My WP Ghost plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 5.0.25. This is due a logic flaw within the brute_math_authenticate function. This makes it possible for unauthenticated attackers to bypass CAPTCHA by omitting the `brute_ck` parameter from the authentication re...
- CVSS:
- 5.3
- Affected:
- up to 5.0.25
- Fixed in:
- 5.0.26
- Disclosed:
- Aug 22, 2023
CVE-2023-34001 on NVD →
Hide My WP Ghost – Security Plugin <= 5.0.18 - IP Address Spoofing to Protection Mechanism Bypass
medium
The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For...
- CVSS:
- 6.5
- Affected:
- up to 5.0.18
- Fixed in:
- 5.0.20
- Disclosed:
- May 8, 2023
CVE-2022-4537 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database