Green Hat Security Advisory · GH-ADV-2026-002
CVE-2026-86796
Unauthenticated protection bypass in Hide My WP Ghost
On sites with WooCommerce active, Hide My WP Ghost 7.0.10 can treat an attacker-supplied request parameter as proof of a WooCommerce request and skip its firewall, threat detection, and URL-hiding checks. An unauthenticated request can then expose login and admin URLs the plugin was configured to conceal.
CVE assignment and research role
Assigning CNA: WPScan. Green Hat Security's role in this record is Researcher; Green Hat did not assign this CVE ID. View the WPScan record ↗
Overview
Summary
On sites with WooCommerce active, Hide My WP Ghost 7.0.10 can treat an attacker-supplied request parameter as proof of a WooCommerce request and skip its firewall, threat detection, and URL-hiding checks. An unauthenticated request can then expose login and admin URLs the plugin was configured to conceal.
Watch
Video Overview
Vulnerability Classification
Vulnerability type
Protection Mechanism Bypass
Weakness
CWE-693
Affected component
WooCommerce request detection and security protection controls
CVSS 3.1
5.3 · Medium
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Security Impact
A crafted unauthenticated request can bypass the plugin's firewall and threat detection for that request and reveal login or admin URLs the site intended to hide. The controlled test demonstrated a protection bypass; it did not establish account compromise or code execution. The bypass is scoped to affected requests, rather than a permanent change to the site's configuration.
Affected Products
Hide My WP Ghost WordPress plugin versions 7.0.10 (before 7.0.11). The CVE record lists unaffected as its default status for versions outside the stated range.
Component: WooCommerce request detection and security protection controls
Fixed version: 7.0.11 or later
Technical Details
With WooCommerce active, Hide My WP Ghost loads compatibility logic that checks whether certain WooCommerce request markers are present in the query string or request body. In version 7.0.10, the presence check is enough to set per-request filters that skip URL hiding, the firewall, and threat detection. The code does not first verify that the request is a legitimate WooCommerce operation. An unauthenticated client can therefore supply a marker on an otherwise ordinary request and cross the trust boundary between compatibility handling and security enforcement. WPScan scheduled publication of its proof of concept for September 30, 2026.
This public record provides enough information to identify the vulnerability and its root cause without unnecessarily publishing weaponized exploit material.
Defensive lesson
Verify the origin and context of a request before allowing a compatibility exception to turn off security controls.
Research evidence
Controlled Lab Validation
Kenny Ho reproduced the behavior in an isolated WordPress lab with WooCommerce 11.1.0, Hide My WP Ghost 7.0.10, and the plugin firewall enabled.
Ordinary request
Returned the normal page with HTTP 200.
Request containing a firewall test string
The plugin blocked it with HTTP 403.
The same test string with an attacker-supplied WooCommerce marker
The firewall block disappeared and the normal page returned with HTTP 200.
The blocked control and the otherwise identical bypass request show that the marker changed the security decision. The observation supports a per-request bypass in this tested configuration; it does not imply that every WordPress installation has WooCommerce active.
Attack Requirements
- The site must run the affected Hide My WP Ghost version with the relevant protections enabled.
- WooCommerce must be active for the affected compatibility logic to load; this was the verified lab configuration.
- The attacker can send an HTTP request without authenticating.
- No victim interaction is required according to the published CVSS vector.
Remediation
Fixed version: 7.0.11 or later
Guidance: Update Hide My WP Ghost to version 7.0.11 or later.
- Identify WordPress sites running Hide My WP Ghost, especially sites with WooCommerce active.
- Confirm the installed plugin version is 7.0.11 or later on each affected site.
- After updating, confirm the configured firewall, threat detection, and URL-hiding controls remain enabled.
Disclosure Timeline
Controlled lab validation
Kenny Ho reproduced the bypass with blocking and baseline controls in a WordPress and WooCommerce test environment.
WPScan record published
WPScan publicly documented the issue and identified version 7.0.11 as the fix.
CVE record published
WPScan published the official CVE record, crediting the finder as Kenny.
The official CVE record credits the finder as Kenny and WPScan as coordinator. Green Hat Security identifies the researcher as Kenny Ho. A private report date is not listed in the public sources.
Researcher Credit
- Kenny Ho — Green Hat Security
Coordination and CVE Attribution
Kenny Ho of Green Hat Security found the issue and is credited as Kenny in the official CVE record. WPScan assigned and coordinated the CVE.
Green Hat Security did not reserve or assign the CVE ID.
The official CVE record credits the finder as Kenny and WPScan as coordinator. Green Hat Security identifies the researcher as Kenny Ho. A private report date is not listed in the public sources.