Server-Side Request Forgery Vulnerability in John Darrel Hide My WP Ghost Plugin
CVE-2026-81806

7.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
8 September 2026

What is CVE-2026-81806?

A Server-Side Request Forgery (SSRF) vulnerability exists in the John Darrel Hide My WP Ghost plugin, allowing an attacker to send unauthorized requests from the server. This issue can lead to sensitive data exposure and other potential security risks. Affected versions of the plugin range from n/a to 7.0.09, necessitating prompt updates to mitigate potential threats.

Affected Version(s)

Hide My WP Ghost <= 7.0.09

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal | Patchstack
.