{"id":"CVE-2026-86796","title":"The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attack…","summary":"The Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attack…","severity":"medium","cvss":5.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-693"],"product":"Hide My WP Ghost","affected":["hide_my_wp_ghost >= 7.0.10 < 7.0.11"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:08:32.830","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86796","references":[{"url":"https://wpscan.com/vulnerability/38baa866-c8a3-4c92-b7c8-8485e7c2a9b0/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"epss":0.00251,"epssPercentile":0.16778,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-18T10:56:15.450762Z"},"ingestedAt":"2026-09-18T06:36:37.990Z","slug":"CVE-2026-86796","body":"## Overview\n\nThe Hide My WP Ghost WordPress plugin before 7.0.11 does not verify that a request is a genuine WooCommerce request before disabling its firewall, threat-detection and login/URL-hiding protections, treating the mere presence of an attacker-suppliable request parameter as sufficient, which allows unauthenticated attackers to disable those protections and re-expose the concealed login and admin URLs on any request.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":29,"depthScoreParts":{"impact":29.2,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}