CVE-2026-86800: CWE-693 Protection Mechanism Failure in Hide My WP Ghost
The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing unauthenticated attackers to re-expose the concealed WordPress login page location.
AI Analysis
Technical Summary
The Hide My WP Ghost WordPress plugin prior to version 7.0.11 contains a protection mechanism failure (CWE-693) where it does not correctly validate loopback security-check requests. When the verification value in such a request is missing or incorrect, the plugin disables its login and URL hiding protection. Since any visitor can trigger this condition, unauthenticated attackers can cause the login page location to be revealed, defeating the plugin's intended concealment.
Potential Impact
An unauthenticated attacker can cause the plugin to disable its login and URL hiding protection, exposing the WordPress login page location. This exposure may increase the risk of targeted attacks against the login interface, but does not directly lead to confidentiality, integrity, or availability compromise according to the CVSS vector (Confidentiality: Low, Integrity: None, Availability: None).
Mitigation Recommendations
Upgrade the Hide My WP Ghost plugin to version 7.0.11 or later where this issue is fixed. No other mitigation is indicated. Patch status is confirmed by the version range affected and the fixed version 7.0.11.
CVE-2026-86800: CWE-693 Protection Mechanism Failure in Hide My WP Ghost
Description
The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing unauthenticated attackers to re-expose the concealed WordPress login page location.
CVSS v3.1
Score 5.3medium
Affected software
Hide My WP Ghost
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Hide My WP Ghost WordPress plugin prior to version 7.0.11 contains a protection mechanism failure (CWE-693) where it does not correctly validate loopback security-check requests. When the verification value in such a request is missing or incorrect, the plugin disables its login and URL hiding protection. Since any visitor can trigger this condition, unauthenticated attackers can cause the login page location to be revealed, defeating the plugin's intended concealment.
Potential Impact
An unauthenticated attacker can cause the plugin to disable its login and URL hiding protection, exposing the WordPress login page location. This exposure may increase the risk of targeted attacks against the login interface, but does not directly lead to confidentiality, integrity, or availability compromise according to the CVSS vector (Confidentiality: Low, Integrity: None, Availability: None).
Mitigation Recommendations
Upgrade the Hide My WP Ghost plugin to version 7.0.11 or later where this issue is fixed. No other mitigation is indicated. Patch status is confirmed by the version range affected and the fixed version 7.0.11.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-09-08T12:19:54.151Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6aacde7455bf5e2cf5a03560
Added to database: 09/18/2026, 06:47:16 UTC
Last enriched: 09/18/2026, 07:01:43 UTC
Last updated: 09/18/2026, 22:25:28 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.