Executive brief
Hide My WP Ghost is a WordPress plugin used to protect websites by hiding WordPress configuration and metadata. An unauthenticated attacker can exploit a server-side request forgery vulnerability to make the server connect to internal systems and extract sensitive data, potentially bypassing network-level security controls and exposing internal services or data behind firewalls.
Technical details
Hide My WP Ghost versions through 7.0.09 contain a server-side request forgery (SSRF) vulnerability that allows an unauthenticated attacker to make arbitrary HTTP requests from the server. The vulnerability is triggered via the plugin without requiring authentication or user interaction. An attacker can leverage this to access internal services, retrieve sensitive data from behind firewalls, perform port scanning, or interact with internal APIs. The issue has been patched in version 7.0.10 and later.
Affected products
- John Darrel Hide My WP Ghost through 7.0.09
Timeline
- 2026-09-08: disclosed
- 2026-09-07: advisory: Patchstack advisory published
- 2026-09-07: patched: Fix available in version 7.0.10 or later