WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro WP Ghost?

Hide and Secure WP paths with the complete WP security suite for Site Hardening. Includes 8G Firewall, Brute Force protection, and Passkeys.

Qué hace este plugin

  • Slug: hide-my-wp
  • Autor: John Darrel
  • 80000+ instalaciones activas
  • 90/100 calificación (371 reseñas en wordpress.org)
  • 2696297 descargas totales
  • En WordPress.org desde 2016-07-01

Brute Forcefirewallhide my wploginsecurity

Estado de mantenimiento

  • Última actualización: 2026-07-20 11:52am GMT
  • Probado hasta WordPress: 7.0.2
  • Requiere PHP: 7.4+

Vulnerabilidades conocidas

8 CVEs conocidos registrados para WP Ghost.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2026-39484 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 7.0.00 Media 4,7 < 7.0.00 7.0.00 2026-03-18
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] <= 6.2.12 (unfixed) Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Alta 7,1 < 6.2.12 6.2.12 2026-01-13
CVE-2025-26909 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.02 Control incorrecto del nombre de archivo en una sentencia include/require de PHP (inclusión remota de archivos PHP / RFI) Crítica 9,6 < 5.4.02 5.4.02 2025-03-19
CVE-2024-13794 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.01 Fallo de un mecanismo de protección Media 5,3 < 5.4.01 5.4.01 2025-02-11
CVE-2024-10825 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.3.02 Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) Media 6,1 < 5.3.02 5.3.02 2024-11-14
CVE-2024-6420 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.2.02 Exposición de información sensible a un actor no autorizado Alta 8,6 < 5.2.02 5.2.02 2024-07-02
CVE-2023-34001 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.26 Restricción incorrecta de intentos excesivos de autenticación Media 5,3 < 5.0.26 5.0.26 2023-08-22
CVE-2022-4537 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.20 Verificación insuficiente de la autenticidad de los datos Media 6,5 < 5.0.20 5.0.20 2023-05-08

CVE-2026-39484

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to 7.0.00 (exclusive). This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] <= 6.2.12 (unfixed)

The Hide My WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-26909

The Hide My WP Ghost plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.01. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2024-13794

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login page location.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-10825

The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrative user into performing an action such as clicking on a link.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

CVE-2024-6420

The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 5.2.01. This is due to the plugin not prevent redirects to the login page when gravity forms is installed. This makes it possible for unauthenticated attackers to find the login page when it has been hidden.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2023-34001

The Hide My WP Ghost plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 5.0.25. This is due a logic flaw within the brute_math_authenticate function. This makes it possible for unauthenticated attackers to bypass CAPTCHA by omitting the `brute_ck` parameter from the authentication request.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2022-4537

The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address from logging in.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: CVE.org

+ 3 vulnerabilidades conocidas más
CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 2.0.03 Desconocido < 2.0.03 2.0.03 2018-09-15
CVE-2025-2056 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.02 Path Traversal relativo (recorrido de ruta relativa) Alta 7,5 < 5.4.02 5.4.02 0000-00-00
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 2.0.03 Desconocido < 2.0.03 2.0.03

WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 2.0.03

SQL Injection (SQLi) vulnerability discovered by Jonas Lejon in the WordPress Hide My WP Ghost plugin (versions <= 2.0.02).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Patchstack

CVE-2025-2056

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it possible for unauthenticated attackers to read the contents of specific file types on the server, which can contain sensitive information.

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 2.0.03

Versions below 2.0.03 are vulnerable for SQL Injection and Script Injection. Fixed in version 2.0.03 released on 2018-09-15

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: WPScan

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.