CVE-2026-86800
Last modified
CVE-2026-86800 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing unauthenticated attackers to re-expose the concealed WordPress login page location..
Description
The Hide My WP Ghost WordPress plugin before 7.0.11 does not properly validate a loopback security-check request before disabling its login and URL hiding protection, dropping that protection precisely when the request's verification value is missing or incorrect, which any visitor can arrange, allowing unauthenticated attackers to re-expose the concealed WordPress login page location.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Unknown | Hide My WP Ghost | < 7.0.11 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-86800?
How severe is CVE-2026-86800?
How do I fix CVE-2026-86800?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8679The AudioIgniter plugin for WordPress is vulnerable to Insec…7.5
- CVE-2026-86790The WP Highlight Box WordPress plugin through 1.0 does not e…6.8
- CVE-2026-86792Apache Airflow Apache Kafka provider versions 1.15.0 before …8.8
- CVE-2026-86793SGLang allows unauthenticated pickle deserialization through…9.8
- CVE-2026-86796The Hide My WP Ghost WordPress plugin before 7.0.11 does not…5.3
- CVE-2026-8680Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-86801The To Do List Member WordPress plugin from 1.4 through 1.6 …8.8
- CVE-2026-86802The To Do List Member WordPress plugin through 1.6 does not …3.7
- CVE-2026-86804A vulnerability was identified in seakee CPA-Manager-Plus up…5.3
- CVE-2026-86805A time-of-check to time-of-use (TOCTOU) race condition in th…6.3
- CVE-2026-86806A weakness has been identified in opengeos GeoLibre up to 2.…7.3
- CVE-2026-86808A security vulnerability has been detected in moltis-org mol…7.3
Are you affected by CVE-2026-86800?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
