> ## Content Index
> Fetch the complete content index at: https://darkwebinformer.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# CVE-2025-26909: WordPress Hide My WP Ghost Plugin <= 5.4.01 is vulnerable to Local File Inclusion
- URL: https://darkwebinformer.com/wordpress-hide-my-wp-ghost-plugin-5-4-01-is-vulnerable-to-local-file-inclusion/
- Published: 2025-03-27T17:25:27.000Z
- Updated: 2025-09-04T22:23:10.000Z
- Author: Dark Web Informer
- Tags: Vulnerabilities

🚨 Critical Security Vulnerability  
🆔 CVE-2025-26909  
💣 CVSS Score: 9.6  
📅 Published Date: 2025-03-27

⚠️ Details: Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through 5.4.01.

🛠 References:  
🔗 NIST: <https://nvd.nist.gov/vuln/detail/CVE-2025-26909>  
🔗 Patchstack: <https://patchstack.com/database/wordpress/plugin/hide-my-wp/vulnerability/wordpress-hide-my-wp-ghost-plugin-5-4-01-local-file-inclusion-to-rce-vulnerability?%5Fs%5Fid=cve>