Back to CVE List

CVE-2026-11870

Vulnerability Description

The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05's own brute-force protection and to downgrade its firewall by matching a hardcoded whitelisted IP range.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
WP Ghost (Hide My WP Ghost)

External References

Discussion (0)

Add Comment

No comments yet. Be the first!