PT-2025-12374 · WordPress · Wp Ghost

Dimas Maulana

·

Published

2025-03-20

·

Updated

2025-06-23

·

CVE-2025-26909

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Hide My WP Ghost versions n/a through 5.4.01
Description The issue affects the Hide My WP Ghost plugin, allowing PHP Local File Inclusion due to improper control of filename for include/require statement in PHP program. This flaw can be exploited for remote code execution, potentially affecting over 200,000 sites using the WP Ghost plugin. The vulnerability arises from inadequate input validation in the showFile() function.
Recommendations For Hide My WP Ghost versions n/a through 5.4.01, update to version 5.4.02 or 5.4.03 to fix the issue. As a temporary workaround, consider restricting access to the showFile() function until a patch is available.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-26909

Affected Products

Wp Ghost