---
id: CVE-2026-81806
title: >-
  Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP
  Ghost allows Server Side Request Forgery.


  This issue affects Hide My WP Ghost: from n/a through 7.0.09.
summary: >-
  Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP
  Ghost allows Server Side Request Forgery.


  This issue affects Hide My WP Ghost: from n/a through 7.0.09.
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-918
vendor: John Darrel
product: hide-my-wp
affected:
  - hide-my-wp >= n/a <= 7.0.09
published: '2026-09-08'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T13:12:58.310'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81806'
references:
  - url: >-
      https://patchstack.com/database/wordpress/plugin/hide-my-wp/vulnerability/wordpress-hide-my-wp-ghost-plugin-7-0-09-server-side-request-forgery-ssrf-vulnerability?_s_id=cve
    label: audit@patchstack.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T09:51:15.749944Z'
epss: 0.00266
epssPercentile: 0.16531
ingestedAt: '2026-09-08T15:33:26.982Z'
---

## Overview

Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery.

This issue affects Hide My WP Ghost: from n/a through 7.0.09.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
