critical CVSS 9.6

CVE-2025-26909·PHP vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through <= 5.4.01.

Severity
critical
Software
PHP
Fixed in
5.4.02
Published
2025-03-27

Affected versions

Until: 5.4.02

Fixed in: 5.4.02

How to fix this CVE

Update the Hide My WP Ghost WordPress plugin to version 5.4.02 or later immediately to patch the local file inclusion vulnerability. This flaw allows attackers to read arbitrary files from your server and potentially execute remote code. Verify the update is applied and test your site functionality to ensure compatibility.

sudo dnf update php

Defensia detects this vulnerability

What an exploitation attempt looks like

Sample log line indicative of exploitation attempts:

POST|GET request to WordPress admin or plugin paths containing file inclusion parameters (e.g., `include=`, `require=`, `file=`) combined with traversal sequences (`../`, `..\`) or PHP wrappers (`php://filter/`, `file://`) targeting sensitive system files like `/etc/passwd` or `/wp-config.php`

WAF mitigation (if patching is not yet possible)

Add this rule to your WAF to block exploitation attempts while you schedule the patch.

Implement WAF rules to block requests containing PHP file inclusion keywords (php://, file://, base64_decode) and path traversal sequences in query parameters and POST data destined for WordPress plugin directories. Enforce strict Content Security Policy headers to prevent inline script execution resulting from file inclusion exploitation.

How to check if you are affected

  1. Check your WordPress plugin version: Log into your WordPress admin panel, navigate to Plugins, and locate 'Hide My WP Ghost' to confirm the current version number
  2. Verify the vulnerable plugin presence: Run `wp plugin list --allow-root 2>/dev/null | grep -i hide-my-wp` on your server via SSH to confirm if the plugin is installed
  3. Examine access logs for suspicious file inclusion patterns: Run `grep -E '(\.\.|\.\./|php://|file://|base64_decode)' /var/log/apache2/access.log | head -20` to identify potential exploitation attempts
  4. Confirm the patch status: After updating, re-check the plugin version in WordPress admin or run `wp plugin list --allow-root 2>/dev/null | grep hide-my-wp` to verify version 5.4.02 or higher is installed

Indicators of compromise

  • User-Agent strings accessing Hide My WP Ghost plugin paths immediately before suspected compromise
  • Requests containing 'php://filter/convert.base64-encode' targeting wp-config.php or plugin files
  • POST requests to Hide My WP admin panels with file parameter values matching system file paths

FAQ

What is CVE-2025-26909?

CVE-2025-26909 is a critical local file inclusion vulnerability in the Hide My WP Ghost WordPress plugin versions up to 5.4.01 that permits attackers to read sensitive files from the server and potentially achieve remote code execution without authentication.

Is CVE-2025-26909 being actively exploited?

No, CVE-2025-26909 is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is available, though the severity warrants immediate patching.

What versions of the Hide My WP Ghost plugin are affected by CVE-2025-26909?

All versions of Hide My WP Ghost through 5.4.01 are vulnerable; version 5.4.02 and later contain the security fix.

How do I check if my server is vulnerable to CVE-2025-26909?

From your WordPress admin dashboard, navigate to Plugins and check if Hide My WP Ghost is installed with a version number of 5.4.01 or earlier; alternatively, use WP-CLI with `wp plugin get hide-my-wp --field=version --allow-root`.

Does Defensia detect CVE-2025-26909?

Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Hide My WP Ghost WordPress plugin is installed on a monitored server, CVE-2025-26909 will appear in your dashboard with remediation steps.

Related PHP CVEs

CVE-2026-39337CVSS 10ChurchCRM is an open-source church management system. Prior to 7.1.0, critical pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The "$dbPassword" variable is not sanitized. This vulnerability exists due to an incomplete fix for CVE-2025-62521. This vulnerability is fixed in 7.1.0.
CVE-2024-5932CVSS 10The GiveWP – Donation Plugin and Fundraising Platform plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.14.1 via deserialization of untrusted input from the 'give_title' parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. The additional presence of a POP chain allows attackers to execute code remotely, and to delete arbitrary files.
CVE-2026-28289CVSS 10FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A patch bypass vulnerability for CVE-2026-27636 in FreeScout 1.8.206 and earlier allows any authenticated user with file upload permissions to achieve Remote Code Execution (RCE) on the server by uploading a malicious .htaccess file using a zero-width space character prefix to bypass the security check. The vulnerability exists in the sanitizeUploadedFileName() function in app/Http/Helper.php. The function contains a Time-of-Check to Time-of-Use (TOCTOU) flaw where the dot-prefix check occurs before sanitization removes invisible characters. This vulnerability is fixed in 1.8.207.
CVE-2025-62521CVSS 10ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the initial installation process, leading to complete server compromise. The vulnerability exists in `setup/routes/setup.php` where user input from the setup form is directly concatenated into a PHP configuration template without any validation or sanitization. Any parameter in the setup form can be used to inject PHP code that gets written to `Include/Config.php`, which is then executed on every page load. This is more severe than typical authenticated RCE vulnerabilities because it requires no credentials and affects the installation process that administrators must complete. Version 5.21.0 patches the issue.
CVE-2025-47916CVSS 10Invision Community 5.0.0 before 5.0.7 allows remote code execution via crafted template strings to themeeditor.php. The issue lies within the themeeditor controller (file: /applications/core/modules/front/system/themeeditor.php), where a protected method named customCss can be invoked by unauthenticated users. This method passes the value of the content parameter to the Theme::makeProcessFunction() method; hence it is evaluated by the template engine. Accordingly, this can be exploited by unauthenticated attackers to inject and execute arbitrary PHP code by providing crafted template strings.

References

Track CVEs across your fleet automatically

Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-26909. Free for 1 server.

Get started free