Open Redirect Vulnerability in WP Ghost (Hide My WP Ghost) Plugin for WordPress
CVE-2026-7527

4.7MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
19 September 2026

What is CVE-2026-7527?

The WP Ghost (Hide My WP Ghost) plugin for WordPress contains an Open Redirect vulnerability that exists in all versions up to and including 7.0.02. This flaw arises from inadequate validation of user input, allowing unauthenticated attackers to redirect users to harmful sites. Attackers can exploit this vulnerability by tricking logged-in users into clicking a specially crafted logout URL. As part of the attack, the target user is logged out of their session via wp_logout(), which makes the malicious redirect irreversible, ultimately compromising user safety.

Affected Version(s)

Hide My WP Ghost – Security & Firewall 0 <= 7.0.02

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

s00me00ne
.