Green Hat Security Advisory · GH-ADV-2026-002

CVE-2026-86796

Unauthenticated protection bypass in Hide My WP Ghost

On sites with WooCommerce active, Hide My WP Ghost 7.0.10 can treat an attacker-supplied request parameter as proof of a WooCommerce request and skip its firewall, threat detection, and URL-hiding checks. An unauthenticated request can then expose login and admin URLs the plugin was configured to conceal.

Medium · CVSS 5.3PatchedPublished

CVE assignment and research role

Assigning CNA: WPScan. Green Hat Security's role in this record is Researcher; Green Hat did not assign this CVE ID. View the WPScan record ↗

Summary

On sites with WooCommerce active, Hide My WP Ghost 7.0.10 can treat an attacker-supplied request parameter as proof of a WooCommerce request and skip its firewall, threat detection, and URL-hiding checks. An unauthenticated request can then expose login and admin URLs the plugin was configured to conceal.

Video Overview

A 28-second motion graphic explains how a crafted request can bypass Hide My WP Ghost firewall, threat-detection, and URL-hiding protections and expose concealed login and admin URLs. It credits Kenny Ho of Green Hat Security as the researcher. Update to version 7.0.11 or later.

Vulnerability Classification

Vulnerability type

Protection Mechanism Bypass

Weakness

CWE-693

Affected component

WooCommerce request detection and security protection controls

CVSS 3.1

5.3 · Medium

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Security Impact

A crafted unauthenticated request can bypass the plugin's firewall and threat detection for that request and reveal login or admin URLs the site intended to hide. The controlled test demonstrated a protection bypass; it did not establish account compromise or code execution. The bypass is scoped to affected requests, rather than a permanent change to the site's configuration.

Affected Products

Hide My WP Ghost WordPress plugin versions 7.0.10 (before 7.0.11). The CVE record lists unaffected as its default status for versions outside the stated range.

Component: WooCommerce request detection and security protection controls

Fixed version: 7.0.11 or later

Technical Details

With WooCommerce active, Hide My WP Ghost loads compatibility logic that checks whether certain WooCommerce request markers are present in the query string or request body. In version 7.0.10, the presence check is enough to set per-request filters that skip URL hiding, the firewall, and threat detection. The code does not first verify that the request is a legitimate WooCommerce operation. An unauthenticated client can therefore supply a marker on an otherwise ordinary request and cross the trust boundary between compatibility handling and security enforcement. WPScan scheduled publication of its proof of concept for September 30, 2026.

This public record provides enough information to identify the vulnerability and its root cause without unnecessarily publishing weaponized exploit material.

Defensive lesson

Verify the origin and context of a request before allowing a compatibility exception to turn off security controls.

Controlled Lab Validation

Kenny Ho reproduced the behavior in an isolated WordPress lab with WooCommerce 11.1.0, Hide My WP Ghost 7.0.10, and the plugin firewall enabled.

Ordinary request

Returned the normal page with HTTP 200.

Request containing a firewall test string

The plugin blocked it with HTTP 403.

The same test string with an attacker-supplied WooCommerce marker

The firewall block disappeared and the normal page returned with HTTP 200.

The blocked control and the otherwise identical bypass request show that the marker changed the security decision. The observation supports a per-request bypass in this tested configuration; it does not imply that every WordPress installation has WooCommerce active.

Attack Requirements

  • The site must run the affected Hide My WP Ghost version with the relevant protections enabled.
  • WooCommerce must be active for the affected compatibility logic to load; this was the verified lab configuration.
  • The attacker can send an HTTP request without authenticating.
  • No victim interaction is required according to the published CVSS vector.

Remediation

Fixed version: 7.0.11 or later

Guidance: Update Hide My WP Ghost to version 7.0.11 or later.

  • Identify WordPress sites running Hide My WP Ghost, especially sites with WooCommerce active.
  • Confirm the installed plugin version is 7.0.11 or later on each affected site.
  • After updating, confirm the configured firewall, threat detection, and URL-hiding controls remain enabled.

Disclosure Timeline

  1. Controlled lab validation

    Kenny Ho reproduced the bypass with blocking and baseline controls in a WordPress and WooCommerce test environment.

  2. WPScan record published

    WPScan publicly documented the issue and identified version 7.0.11 as the fix.

  3. CVE record published

    WPScan published the official CVE record, crediting the finder as Kenny.

The official CVE record credits the finder as Kenny and WPScan as coordinator. Green Hat Security identifies the researcher as Kenny Ho. A private report date is not listed in the public sources.

Researcher Credit

  • Kenny Ho — Green Hat Security

Coordination and CVE Attribution

Kenny Ho of Green Hat Security found the issue and is credited as Kenny in the official CVE record. WPScan assigned and coordinated the CVE.

Green Hat Security did not reserve or assign the CVE ID.

The official CVE record credits the finder as Kenny and WPScan as coordinator. Green Hat Security identifies the researcher as Kenny Ho. A private report date is not listed in the public sources.

References

CVE-2026-86796: Unauthenticated protection bypass in Hide My WP Ghost