CVE-2025-26909: WordPress Hide My WP Ghost plugin <= 5.4.01 - Local File Inclusion to RCE vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through <= 5.4.01.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26909?
CVE-2025-26909 is classified as a high-severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-26909?
To fix CVE-2025-26909, update the Hide My WP Ghost plugin to version 5.4.02 or later.
What type of vulnerability is CVE-2025-26909?
CVE-2025-26909 is an Improper Control of Filename for Include/Require Statement vulnerability, specifically leading to PHP Local File Inclusion.
Which versions of Hide My WP Ghost are affected by CVE-2025-26909?
CVE-2025-26909 affects Hide My WP Ghost from n/a up to and including version 5.4.01.
What are the consequences of exploiting CVE-2025-26909?
Exploiting CVE-2025-26909 can lead to unauthorized remote access and execution of arbitrary code on the affected server.