PT-2025-12374 · WordPress · Wp Ghost
Dimas Maulana
·
Published
2025-03-20
·
Updated
2025-06-23
·
CVE-2025-26909
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Hide My WP Ghost versions n/a through 5.4.01
Description
The issue affects the Hide My WP Ghost plugin, allowing PHP Local File Inclusion due to improper control of filename for include/require statement in PHP program. This flaw can be exploited for remote code execution, potentially affecting over 200,000 sites using the WP Ghost plugin. The vulnerability arises from inadequate input validation in the
showFile() function.Recommendations
For Hide My WP Ghost versions n/a through 5.4.01, update to version 5.4.02 or 5.4.03 to fix the issue. As a temporary workaround, consider restricting access to the
showFile() function until a patch is available.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp Ghost