Junglewise Threat Intelligence

CVE-2026-81806: Hide My WP Ghost server-side request forgery

CVE-2026-81806 · Severity: high · CVSS 7.2 · Published 2026-09-08

Technologies: John Darrel Hide My WP Ghost. Vendors: John Darrel.

Executive brief

Hide My WP Ghost is a WordPress plugin used to protect websites by hiding WordPress configuration and metadata. An unauthenticated attacker can exploit a server-side request forgery vulnerability to make the server connect to internal systems and extract sensitive data, potentially bypassing network-level security controls and exposing internal services or data behind firewalls.

Technical details

Hide My WP Ghost versions through 7.0.09 contain a server-side request forgery (SSRF) vulnerability that allows an unauthenticated attacker to make arbitrary HTTP requests from the server. The vulnerability is triggered via the plugin without requiring authentication or user interaction. An attacker can leverage this to access internal services, retrieve sensitive data from behind firewalls, perform port scanning, or interact with internal APIs. The issue has been patched in version 7.0.10 and later.

Affected products

  • John Darrel Hide My WP Ghost through 7.0.09

Timeline

  • 2026-09-08: disclosed
  • 2026-09-07: advisory: Patchstack advisory published
  • 2026-09-07: patched: Fix available in version 7.0.10 or later

References

Related threats