CVE-2026-7527
Last modified
CVE-2026-7527 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validating user input. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Open Redirect in all versions up to, and including, 7.0.02. This is due to the plugin not properly validating user input. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into clicking on a specially crafted link. Exploitation requires tricking a logged-in user into clicking a crafted logout URL; the victim is fully logged out via wp_logout() before the malicious redirect is issued, making the logout irreversible as part of the attack chain.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| johndarrel | Hide My WP Ghost – Security & Firewall | <= 7.0.02 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-7527?
How severe is CVE-2026-7527?
How do I fix CVE-2026-7527?
How Strix Helps
- One Click Account Takeover in GranolaHow a notification link broke out of Electron and led to a one-click account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7521Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6…5.5
- CVE-2026-7522The Advanced Database Cleaner – Premium plugin for WordPress…8.8
- CVE-2026-7523The Alba Board plugin for WordPress is vulnerable to authori…4.3
- CVE-2026-7524IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code…9.8
- CVE-2026-7525The My Calendar – Accessible Event Manager plugin for WordPr…4.3
- CVE-2026-7526The PDF Embedder plugin for WordPress is vulnerable to Sensi…4.3
- CVE-2026-7528IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of…7.5
- CVE-2026-7529The wiseCampaign – WooCommerce Conversions Made Easy plugin …7.5
- CVE-2026-75307zhitan-ems 1.0.0 is vulnerable to Cross Site Scripting (XSS)…6.1
- CVE-2026-75308yshopmall <=3.3 is vulnerable to Cross Site Scripting (XSS).…6.1
- CVE-2026-7531Use-after-free in PQC hybrid key-share handling. This is an …9.8
- CVE-2026-7532iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME i…7.5
Are you affected by CVE-2026-7527?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
