CVE-2026-11870

The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a trusted proxy before trusting attacker-controllable HTTP headers, allowing unauthenticated attackers to spoof their IP address to bypass the WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05's own brute-force protection and to downgrade its firewall by matching a hardcoded whitelisted IP range.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-30 06:24

Updated : 2026-07-30 19:17


NVD link : CVE-2026-11870

Mitre link : CVE-2026-11870

CVE.ORG link : CVE-2026-11870


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing