Skip to content Dark Web Informer - Cyber Threat Intelligence

CVE-2025-26909: WordPress Hide My WP Ghost Plugin <= 5.4.01 is vulnerable to Local File Inclusion

🚨 Critical Security Vulnerability
🆔 CVE-2025-26909
💣 CVSS Score: 9.6
📅 Published Date: 2025-03-27

⚠️ Details: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through 5.4.01.

🛠 References:
🔗 NIST: https://nvd.nist.gov/vuln/detail/CVE-2025-26909
🔗 Patchstack: https://patchstack.com/database/wordpress/plugin/hide-my-wp/vulnerability/wordpress-hide-my-wp-ghost-plugin-5-4-01-local-file-inclusion-to-rce-vulnerability?_s_id=cve

Latest