CVE Database /
CVE-2025-26909
CVE · Critical
CVE-2025-26909 — WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.02
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-26909
|
WP Ghost (Hide My WP Ghost) – Security & Firewall [hide-my-wp] < 5.4.02 |
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') |
Critical
9.6
|
< 5.4.02
|
5.4.02 |
2025-03-19 |
—
|
CVE-2025-26909
The Hide My WP Ghost plugin for WordPress contains a security flaw that enables unverified users to inject arbitrary server-side files into the application, allowing malicious PHP code to run on the system. This vulnerability affects all versions up to 5.4.01, potentially leading to unauthorized access to sensitive data or execution of malicious scripts via uploaded images and other seemingly innocuous file types.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings