Hide and Secure WP paths with the complete WP security suite for Site Hardening. Includes 8G Firewall, Brute Force protection, and Passkeys.
Qué hace este plugin
- Slug:
hide-my-wp
- Autor: John Darrel
- 80000+ instalaciones activas
- 90/100 calificación (371 reseñas en wordpress.org)
- 2696297 descargas totales
- En WordPress.org desde 2016-07-01
Brute Forcefirewallhide my wploginsecurity
Estado de mantenimiento
- Última actualización: 2026-07-20 11:52am GMT
- Probado hasta WordPress: 7.0.2
- Requiere PHP: 7.4+
Vulnerabilidades conocidas
8 CVEs conocidos registrados para WP Ghost.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
CVE-2026-39484
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 7.0.00 |
— |
Media
4,7
|
< 7.0.00
|
7.0.00 |
2026-03-18 |
—
|
|
—
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] <= 6.2.12 (unfixed) |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Alta
7,1
|
< 6.2.12
|
6.2.12 |
2026-01-13 |
—
|
|
CVE-2025-26909
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.02 |
Control incorrecto del nombre de archivo en una sentencia include/require de PHP (inclusión remota de archivos PHP / RFI) |
Crítica
9,6
|
< 5.4.02
|
5.4.02 |
2025-03-19 |
—
|
|
CVE-2024-13794
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.01 |
Fallo de un mecanismo de protección |
Media
5,3
|
< 5.4.01
|
5.4.01 |
2025-02-11 |
—
|
|
CVE-2024-10825
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.3.02 |
Neutralización incorrecta de la entrada al generar la página web (Cross-site Scripting / XSS) |
Media
6,1
|
< 5.3.02
|
5.3.02 |
2024-11-14 |
—
|
|
CVE-2024-6420
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.2.02 |
Exposición de información sensible a un actor no autorizado |
Alta
8,6
|
< 5.2.02
|
5.2.02 |
2024-07-02 |
—
|
|
CVE-2023-34001
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.26 |
Restricción incorrecta de intentos excesivos de autenticación |
Media
5,3
|
< 5.0.26
|
5.0.26 |
2023-08-22 |
—
|
|
CVE-2022-4537
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.20 |
Verificación insuficiente de la autenticidad de los datos |
Media
6,5
|
< 5.0.20
|
5.0.20 |
2023-05-08 |
—
|
CVE-2026-39484
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to 7.0.00 (exclusive). This is due to insufficient validation on a redirect url. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] <= 6.2.12 (unfixed)
The Hide My WP plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 6.2.12 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-26909
The Hide My WP Ghost plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 5.4.01. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where images and other “safe” file types can be uploaded and included.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2024-13794
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the plugin not properly restricting the /wp-register.php path. This makes it possible for unauthenticated attackers to discover the hidden login page location.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-10825
The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick an administrative user into performing an action such as clicking on a link.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
CVE-2024-6420
The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Login Page Disclosure in all versions up to, and including, 5.2.01. This is due to the plugin not prevent redirects to the login page when gravity forms is installed. This makes it possible for unauthenticated attackers to find the login page when it has been hidden.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2023-34001
The Hide My WP Ghost plugin for WordPress is vulnerable to CAPTCHA Bypass in versions up to, and including, 5.0.25. This is due a logic flaw within the brute_math_authenticate function. This makes it possible for unauthenticated attackers to bypass CAPTCHA by omitting the `brute_ck` parameter from the authentication request.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2022-4537
The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions on where the IP Address information is being retrieved for request logging and login restrictions. Attackers can supply the X-Forwarded-For header with with a different IP Address that will be logged and can be used to bypass settings that may have blocked out an IP address from logging in.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
CVE.org
+ 3 vulnerabilidades conocidas más
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 2.0.03 |
— |
Desconocido
|
< 2.0.03
|
2.0.03 |
2018-09-15 |
—
|
|
CVE-2025-2056
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.02 |
Path Traversal relativo (recorrido de ruta relativa) |
Alta
7,5
|
< 5.4.02
|
5.4.02 |
0000-00-00 |
—
|
|
—
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 2.0.03 |
— |
Desconocido
|
< 2.0.03
|
2.0.03 |
— |
—
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 2.0.03
SQL Injection (SQLi) vulnerability discovered by Jonas Lejon in the WordPress Hide My WP Ghost plugin (versions <= 2.0.02).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Patchstack
CVE-2025-2056
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it possible for unauthenticated attackers to read the contents of specific file types on the server, which can contain sensitive information.
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 2.0.03
Versions below 2.0.03 are vulnerable for SQL Injection and Script Injection. Fixed in version 2.0.03 released on 2018-09-15
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
WPScan
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas