CVE-2025-26909·PHP vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through <= 5.4.01.
- Severity
- critical
- Software
- PHP
- Fixed in
- 5.4.02
- Published
- 2025-03-27
Affected versions
Until: 5.4.02
Fixed in: 5.4.02
How to fix this CVE
Update the Hide My WP Ghost WordPress plugin to version 5.4.02 or later immediately to patch the local file inclusion vulnerability. This flaw allows attackers to read arbitrary files from your server and potentially execute remote code. Verify the update is applied and test your site functionality to ensure compatibility.
sudo dnf update phpDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
POST|GET request to WordPress admin or plugin paths containing file inclusion parameters (e.g., `include=`, `require=`, `file=`) combined with traversal sequences (`../`, `..\`) or PHP wrappers (`php://filter/`, `file://`) targeting sensitive system files like `/etc/passwd` or `/wp-config.php`WAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement WAF rules to block requests containing PHP file inclusion keywords (php://, file://, base64_decode) and path traversal sequences in query parameters and POST data destined for WordPress plugin directories. Enforce strict Content Security Policy headers to prevent inline script execution resulting from file inclusion exploitation.How to check if you are affected
- Check your WordPress plugin version: Log into your WordPress admin panel, navigate to Plugins, and locate 'Hide My WP Ghost' to confirm the current version number
- Verify the vulnerable plugin presence: Run `wp plugin list --allow-root 2>/dev/null | grep -i hide-my-wp` on your server via SSH to confirm if the plugin is installed
- Examine access logs for suspicious file inclusion patterns: Run `grep -E '(\.\.|\.\./|php://|file://|base64_decode)' /var/log/apache2/access.log | head -20` to identify potential exploitation attempts
- Confirm the patch status: After updating, re-check the plugin version in WordPress admin or run `wp plugin list --allow-root 2>/dev/null | grep hide-my-wp` to verify version 5.4.02 or higher is installed
Indicators of compromise
- User-Agent strings accessing Hide My WP Ghost plugin paths immediately before suspected compromise
- Requests containing 'php://filter/convert.base64-encode' targeting wp-config.php or plugin files
- POST requests to Hide My WP admin panels with file parameter values matching system file paths
FAQ
What is CVE-2025-26909?
CVE-2025-26909 is a critical local file inclusion vulnerability in the Hide My WP Ghost WordPress plugin versions up to 5.4.01 that permits attackers to read sensitive files from the server and potentially achieve remote code execution without authentication.
Is CVE-2025-26909 being actively exploited?
No, CVE-2025-26909 is not currently listed in CISA's Known Exploited Vulnerabilities catalog, and no public exploit code is available, though the severity warrants immediate patching.
What versions of the Hide My WP Ghost plugin are affected by CVE-2025-26909?
All versions of Hide My WP Ghost through 5.4.01 are vulnerable; version 5.4.02 and later contain the security fix.
How do I check if my server is vulnerable to CVE-2025-26909?
From your WordPress admin dashboard, navigate to Plugins and check if Hide My WP Ghost is installed with a version number of 5.4.01 or earlier; alternatively, use WP-CLI with `wp plugin get hide-my-wp --field=version --allow-root`.
Does Defensia detect CVE-2025-26909?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Hide My WP Ghost WordPress plugin is installed on a monitored server, CVE-2025-26909 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-26909. Free for 1 server.
Get started free