CVE · Medium

CVE-2022-4537 — WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.20

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2022-4537 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.0.20 Insufficient Verification of Data Authenticity Medium 6.5 < 5.0.20 5.0.20 2023-05-08

CVE-2022-4537

The Hide My WP Ghost – Security Plugin for WordPress through version 5.0.18 contains an IP address spoofing vulnerability stemming from inadequate validation of IP sources during request logging and login restriction enforcement. Attackers can manipulate the X-Forwarded-For header to spoof their IP address, which the plugin then logs and uses for access control decisions, allowing them to circumvent IP-based login blocks that administrators have configured.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.