WP Ghost (Hide My WP Ghost) <= 7.0.12 - Unauthenticated Firewall and Brute Force Protection Bypass via Forged Login Cookie
- ID
- WPSEC-2026-0550
- Plugin
- Hide My WP Ghost – Security & Firewall (hide-my-wp)
- Affected
- from 7.0.00 before 7.0.13
- Remediation
- Update to 7.0.13 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- Weakness
- CWE-565
- Usage
- Plugin Low · Affected versions None seen among sites WPSec scans, 2026-10-07
- Attack surface
- WP Ghost (Hide My WP Ghost) on WPSec AttackSurface
- Fix released
- Published
Description
The Hide My WP Ghost plugin for WordPress is vulnerable to a protection bypass in versions 7.0.00 up to, and including, 7.0.12. This is due to the firewall and brute force checks, which run before WordPress can verify login cookies, treating any request that carries a cookie named like a WordPress logged-in cookie as coming from a logged-in user without validating the cookie's signature. This makes it possible for unauthenticated attackers to add a forged login cookie to their requests and skip the plugin's firewall rules, IP ban list and threat detection, as well as its login brute force protection (attempt limits, lockouts and CAPTCHA), when those features are enabled.
References
- https://wpsec.com/vuln/WPSEC-2026-0550/
- https://plugins.svn.wordpress.org/hide-my-wp/tags/7.0.13/
- https://wordpress.org/plugins/hide-my-wp/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS