Junglewise Threat Intelligence

CVE-2026-86796: Hide My WP Ghost firewall bypass via WooCommerce parameter

CVE-2026-86796 · Severity: medium · CVSS 5.3 · Published 2026-09-18

Executive brief

Hide My WP Ghost is a WordPress plugin that protects websites by concealing admin and login URLs and activating firewall and threat-detection rules. The plugin fails to verify that requests are genuine WooCommerce requests before disabling these protections, allowing unauthenticated attackers to simply add a request parameter to bypass the firewall, expose hidden URLs, and potentially gain unauthorized access to the admin panel.

Technical details

The vulnerability is an authentication/request validation bypass in Hide My WP Ghost versions before 7.0.11. The plugin accepts an attacker-supplied WooCommerce request parameter and, without verifying the legitimacy of the request, disables its firewall, threat-detection, and login/URL-hiding protections. This is a broken access control vulnerability triggered by the mere presence of a request parameter. No authentication is required and the attack is network-accessible; an attacker can craft a malicious request to any page on the site with the spoofed parameter to re-expose the concealed login and admin URLs. The fix is available in version 7.0.11.

Affected products

  • WP Ghost Hide My WP Ghost before 7.0.11

Timeline

  • 2026-09-16: disclosed
  • 2026-09-18: advisory
  • 2026-09-16: patched: Fixed in version 7.0.11

References