WordPress Plugin Vulnerabilities
WP Ghost (Hide My WP Ghost) 7.0.10 - Unauthenticated Firewall, Threat Detection and URL Hiding Bypass via WooCommerce Request Parameters
Description
The plugin does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.
Proof of Concept
Affects Plugins
References
CVE
Miscellaneous
Original Researcher
Kenny
Submitter
Kenny
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-16 (about 2 days ago)
Added
2026-09-16 (about 1 day ago)
Last Updated
2026-09-16 (about 1 day ago)