Authentication Flaw in Hide My WP Ghost Plugin by WordPress
CVE-2026-59546
7.4HIGH
What is CVE-2026-59546?
The Hide My WP Ghost plugin for WordPress has a significant vulnerability associated with broken authentication, affecting versions up to 7.0.06. This flaw allows unauthorized users to bypass two-factor authentication mechanisms, potentially granting them access to subscriber accounts. Proper mitigation measures should be taken to protect against unwanted exploitation of this vulnerability, ensuring that user credentials remain secure.
Affected Version(s)
Hide My WP Ghost <= 7.0.06
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Ananda Dhakal (Patchstack) | Patchstack Bug Bounty Program