VYPR

Hide My Wp Ghost

by WordPress

Source repositories

CVEs (12)

  • CVE-2025-26909CriMar 27, 2025
    risk 0.62cvss 9.6epss 0.01

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through <= 5.4.01.

  • CVE-2024-6420HigJul 23, 2024
    risk 0.56cvss 8.6epss 0.02

    The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the hidden login page.

  • CVE-2025-2056HigMar 14, 2025
    risk 0.49cvss 7.5epss 0.01

    The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it possible for unauthenticated attackers to read the contents of specific file types…

  • CVE-2026-81806HigSep 8, 2026
    risk 0.47cvss 7.2epss 0.00

    Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.

  • CVE-2026-86800MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any…

  • CVE-2026-86796MedSep 18, 2026
    risk 0.34cvss 5.3epss 0.00

    The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as…

  • CVE-2024-13794MedFeb 12, 2025
    risk 0.34cvss 5.3epss 0.00

    The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for…

  • CVE-2023-34001MedJun 4, 2024
    risk 0.34cvss 5.3epss 0.00

    Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects Hide My WP Ghost: from n/a through 5.0.25.

  • CVE-2024-10825MedNov 15, 2024
    risk 0.33cvss 6.1epss 0.00

    The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated…

  • CVE-2026-39484MedApr 8, 2026
    risk 0.31cvss 4.7epss 0.00

    URL Redirection to Untrusted Site ('Open Redirect') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows Phishing.This issue affects Hide My WP Ghost: from n/a through < 7.0.00.

  • CVE-2026-7527MedSep 19, 2026
    risk 0.24cvss 4.7epss 0.00

    The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validating user input. This makes it possible for unauthenticated attackers to…

  • CVE-2026-59546HigJul 27, 2026
    risk 0.00cvss 7.4epss 0.00

    Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 versions.