cleantalk
Vulnerabilities and Security Researches

Hide My WP Ghost – Security Plugin, CVE-2025-26909

CVE, Research URL

CVE-2025-26909

Published on
Mar 27, 2025
Research Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through 5.4.01.
Affected versions
max 5.4.02.
Status
vulnerable