Skip to main content

Vendor/product archive

wpplugins / hide_my_wp_ghost CVEs

Beta · best-effort

7 CVEs tagged to wpplugins / hide_my_wp_ghost1 Critical, 2 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2025-26909

Published Mar 27, 2025

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local F…

CVSS 9.6 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-2056

Published Mar 14, 2025

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function.…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-13794

Published Feb 12, 2025

The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Login Page Dislcosure in all versions up to, and including, 5.3.02. This is due to the…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-10825

Published Nov 15, 2024

The Hide My WP Ghost – Security & Firewall plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the URL in all versions up to, and including, 5.3.01 due to ins…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-6420

Published Jul 23, 2024

The Hide My WP Ghost WordPress plugin before 5.2.02 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to a…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34001

Published Jun 4, 2024

Improper Restriction of Excessive Authentication Attempts vulnerability in WPPlugins – WordPress Security Plugins Hide My WP Ghost allows Functionality Bypass.This issue affects H…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-4537

Published May 9, 2023

The Hide My WP Ghost – Security Plugin plugin for WordPress is vulnerable to IP Address Spoofing in versions up to, and including, 5.0.18. This is due to insufficient restrictions…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1