WordPress Plugin Vulnerabilities

WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters

Description

The plugin does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.

Proof of Concept

Affects Plugins

Fixed in 7.0.11

References

Miscellaneous

Original Researcher
Kenny
Submitter
Kenny
Verified
Yes

Timeline

Publicly Published
2026-09-16 (about 2 days ago)
Added
2026-09-16 (about 1 day ago)
Last Updated
2026-09-16 (about 1 day ago)

Other