Junglewise Threat Intelligence

CVE-2026-7527: Hide My WP Ghost open redirect vulnerability

CVE-2026-7527 · Severity: medium · CVSS 4.7 · Published 2026-09-19

Executive brief

The Hide My WP Ghost security plugin for WordPress contains an open redirect flaw that allows attackers to send users to malicious websites. An attacker crafts a logout link and tricks a logged-in user into clicking it; the user is logged out and then silently redirected to an attacker-controlled destination, potentially for phishing or malware distribution.

Technical details

The plugin fails to validate redirect URLs in the logout function, allowing unauthenticated attackers to inject arbitrary redirect destinations. The attack requires social engineering to trick a logged-in user into clicking a malicious logout link. Upon successful exploitation, the victim is logged out and redirected to an attacker-controlled URL, with no mitigation available once the logout is triggered.

Affected products

  • WP Ghost Hide My WP Ghost up to and including 7.0.02

Timeline

  • 2026-09-19: disclosed

References