# WP Ghost (Hide My WP Ghost) <= 7.0.12 - Unauthenticated Firewall and Brute Force Protection Bypass via Forged Login Cookie

- **ID:** WPSEC-2026-0550
- **Plugin:** Hide My WP Ghost – Security & Firewall (`hide-my-wp`), https://wordpress.org/plugins/hide-my-wp/
- **Affected versions:** from 7.0.00 before 7.0.13
- **Fixed in:** 7.0.13 (Update to 7.0.13 or later.)
- **Severity:** Medium 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
- **Weakness:** CWE-565
- **Usage among sites WPSec scans:** plugin Low, affected versions None seen (as of 2026-10-07)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/hide-my-wp
- **Fix released:** 2026-10-04
- **Published:** 2026-10-07
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0550/

## Description

The Hide My WP Ghost plugin for WordPress is vulnerable to a protection bypass in versions 7.0.00 up to, and including, 7.0.12. This is due to the firewall and brute force checks, which run before WordPress can verify login cookies, treating any request that carries a cookie named like a WordPress logged-in cookie as coming from a logged-in user without validating the cookie's signature. This makes it possible for unauthenticated attackers to add a forged login cookie to their requests and skip the plugin's firewall rules, IP ban list and threat detection, as well as its login brute force protection (attempt limits, lockouts and CAPTCHA), when those features are enabled.

## References

- https://wpsec.com/vuln/WPSEC-2026-0550/
- https://plugins.svn.wordpress.org/hide-my-wp/tags/7.0.13/
- https://wordpress.org/plugins/hide-my-wp/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0550/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
