Authentication Flaw in Hide My WP Ghost Plugin by WordPress
CVE-2026-59546

7.4HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
27 July 2026

What is CVE-2026-59546?

The Hide My WP Ghost plugin for WordPress has a significant vulnerability associated with broken authentication, affecting versions up to 7.0.06. This flaw allows unauthorized users to bypass two-factor authentication mechanisms, potentially granting them access to subscriber accounts. Proper mitigation measures should be taken to protect against unwanted exploitation of this vulnerability, ensuring that user credentials remain secure.

Affected Version(s)

Hide My WP Ghost <= 7.0.06

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program
.