CVE-2026-81806
moderateUnauthenticated SSRF in John Darrel Hide My WP Ghost WordPress Plugin
CVE-2026-81806 is a Server-Side Request Forgery (SSRF) flaw (CWE-918) in the Hide My WP Ghost WordPress plugin by John Darrel, affecting all versions through 7.0.09. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:C) indicates it can be triggered over the network without authentication or user interaction, likely by submitting crafted input that causes the server to make unintended requests. Because the scope is changed with low confidentiality and integrity impacts, an attacker may be able to make the affected host request attacker-controlled or internal URLs, potentially probing internal services, local resources, or metadata endpoints. Any WordPress site running Hide My WP Ghost up to and including 7.0.09 is affected. Exploitation status is currently quiet: there is no public proof-of-concept, the flaw is not in CISA KEV, and EPSS assigns it only a 0.2% chance of exploitation within 30 days.
What to do: Update Hide My WP Ghost to the latest patched release (any version newer than 7.0.09) as soon as it is available, and verify the installed version under the WordPress plugins list. In the interim, consider restricting the web server's outbound HTTP requests and review server/WAF logs for unexpected outbound connections or SSRF-style probing. No public PoC or in-the-wild exploitation is known, so patching before broad disclosure is a low-effort, high-value step.
| John Darrel Hide My WP Ghost (WordPress plugin) | all versions through 7.0.09 (n/a to 7.0.09) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
- Ecosystems
- WordPress
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.