CVE · Critical

CVE-2025-26909 — WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.02

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-26909 WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.02 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Critical 9.6 < 5.4.02 5.4.02 2025-03-19

CVE-2025-26909

The Hide My WP Ghost plugin for WordPress contains a security flaw that enables unverified users to inject arbitrary server-side files into the application, allowing malicious PHP code to run on the system. This vulnerability affects all versions up to 5.4.01, potentially leading to unauthorized access to sensitive data or execution of malicious scripts via uploaded images and other seemingly innocuous file types.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.