Executive brief
Hide My WP Ghost is a WordPress security plugin designed to hide the fact that a website is running on WordPress to prevent automated attacks. A vulnerability in this plugin allows attackers to create malicious links that appear to belong to the trusted website but actually redirect users to external, potentially harmful sites. This can be used in phishing campaigns to steal user credentials or distribute malware by leveraging the reputation of the trusted domain.
Technical details
An Open Redirect (CWE-601) vulnerability exists in the John Darrel Hide My WP Ghost plugin for WordPress in versions prior to 7.0.00. The issue stems from insufficient validation of user-supplied input used in redirection targets. An unauthenticated remote attacker can exploit this by crafting a URL that, when clicked by a victim, redirects them from the legitimate site to an arbitrary external domain. While the vulnerability itself does not allow for direct data theft from the server, it is a primary vector for phishing and social engineering attacks. The issue is resolved in version 7.0.00.
Affected products
- John Darrel Hide My WP Ghost up to 7.0.00 (exclusive)
Timeline
- 2026-02-16: other: Vulnerability reported by researcher Or Benit
- 2026-03-18: advisory: Patchstack published advisory details
- 2026-04-08: disclosed: CVE published to NVD
- 2026-03-18: patched: Version 7.0.00 released to address the issue