CVE-2026-11870
Vulnerability Description
The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05's own brute-force protection and to downgrade its firewall by matching a hardcoded whitelisted IP range.
Vulnerability Details
Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
WP Ghost (Hide My WP Ghost)
Discussion (0)
Add Comment
No comments yet. Be the first!