CVE-2026-39484 is an open redirect vulnerability in the Hide My WP Ghost WordPress plugin versions prior to 7.0.00 that could allow attackers to redirect users to untrusted external websites, facilitating phishing attacks. The vulnerability requires no authentication and can be exploited through a network attack with minimal complexity, though user interaction is necessary to trigger the redirect. The vulnerability carries a CVSS score of 4.7 (Medium severity) with a network-based attack vector and low attack complexity. The primary impact is a low confidentiality risk through potential phishing exploitation, with no direct impact to system integrity or availability. The FAUCET Risk Score of 31.0 reflects moderate concern relative to other vulnerabilities. There is currently no evidence of active exploitation in the wild, with the vulnerability absent from CISA's Known Exploited Vulnerabilities catalog and maintaining inactive status on exploit databases. Community attention and exploit code availability appear minimal, though the straightforward nature of open redirect vulnerabilities suggests organizations should prioritize updating to version 7.0.00 or later as a precautionary measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| John Darrel | Hide My WP Ghost | >= 0, <= 7.0.00CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.