Executive brief
Hide My WP Ghost is a WordPress security plugin designed to hide common WordPress paths and protect sites from automated attacks. A security flaw in this plugin allows unauthorized users to bypass authentication mechanisms, including two-factor authentication (2FA). If exploited, an attacker could gain administrative access to the website, potentially leading to full site takeover and data theft.
Technical details
The Hide My WP Ghost plugin for WordPress is vulnerable to an authentication bypass (CWE-639) in versions up to and including 7.0.06. The vulnerability stems from broken authentication logic that allows a user-controlled key to bypass security checks, specifically impacting the two-factor authentication (2FA) feature. Although the attack complexity is rated as high, a successful exploit allows an unauthenticated remote attacker to gain the privileges of higher-level users, potentially including administrators. The issue is resolved in version 7.0.07.
Affected products
- John Darrel Hide My WP Ghost <= 7.0.06
Timeline
- 2026-07-16: other: Reported by researcher
- 2026-07-23: advisory: Patchstack advisory published
- 2026-07-27: disclosed: CVE published to NVD
- 2026-07-27: patched: Version 7.0.07 released