What is CVE-2026-11870?
In the WP Ghost WordPress plugin versions before 7.0.05, client IP information is not verified to originate from a trusted proxy. This allows unauthenticated attackers to spoof their IP address by controlling HTTP headers, bypassing security restrictions imposed by the plugin. Users should immediately update to version 7.0.05 or later.
Azərbaycanca: WP Ghost WordPress plaqini 7.0.05 versiyasından əvvəlki versiyalarda, müştəri IP məlumatının etibarlı proksi vasitəsilə gəldiyini yoxlamır. Bu zəiflik autentifikasiya olunmamış hücumçulara HTTP başlıqlarını manipulyasiya edərək IP ünvanını saxtalaşdırmağa və plaqin tərəfindən tətbiq edilən məhdudiyyətləri keçməyə imkan verir. İstifadəçilər ən qısa zamanda 7.0.05 və ya daha yeni versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
What does the CVE-2026-11870 vulnerability in the WP Ghost plugin allow?
This vulnerability allows unauthenticated attackers to spoof their IP address by controlling HTTP headers, bypassing security restrictions imposed by the plugin.
What should users do to remediate the CVE-2026-11870 vulnerability?
Users should immediately update the WP Ghost plugin to version 7.0.05 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.