Executive brief
Hide My WP Ghost is a WordPress plugin that protects websites by concealing admin and login URLs and activating firewall and threat-detection rules. The plugin fails to verify that requests are genuine WooCommerce requests before disabling these protections, allowing unauthenticated attackers to simply add a request parameter to bypass the firewall, expose hidden URLs, and potentially gain unauthorized access to the admin panel.
Technical details
The vulnerability is an authentication/request validation bypass in Hide My WP Ghost versions before 7.0.11. The plugin accepts an attacker-supplied WooCommerce request parameter and, without verifying the legitimacy of the request, disables its firewall, threat-detection, and login/URL-hiding protections. This is a broken access control vulnerability triggered by the mere presence of a request parameter. No authentication is required and the attack is network-accessible; an attacker can craft a malicious request to any page on the site with the spoofed parameter to re-expose the concealed login and admin URLs. The fix is available in version 7.0.11.
Affected products
- WP Ghost Hide My WP Ghost before 7.0.11
Timeline
- 2026-09-16: disclosed
- 2026-09-18: advisory
- 2026-09-16: patched: Fixed in version 7.0.11