CVE Database /
CVE-2026-11870
CVE
CVE-2026-11870 — WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 7.0.05
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-11870
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 7.0.05 |
Authentication Bypass by Spoofing |
Unknown
|
< 7.0.05
|
7.0.05 |
2026-07-30 |
—
|
CVE-2026-11870
The WP Ghost plugin for WordPress prior to version 7.0.05 fails to properly validate proxy-provided client IP addresses, enabling malicious actors to manipulate their apparent IP address without authentication. This vulnerability allows attackers to circumvent the plugin's own security measures, including brute-force protection and firewall settings, by exploiting a hardcoded whitelisted IP range.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings