CVE-2025-26909

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in John Darrel Hide My WP Ghost hide-my-wp allows PHP Local File Inclusion.This issue affects Hide My WP Ghost: from n/a through <= 5.4.01.
Configurations

Configuration 1 (hide)

cpe:2.3:a:wpplugins:hide_my_wp_ghost:*:*:*:*:*:wordpress:*:*

History

No history.

Information

Published : 2025-03-27 16:15

Updated : 2026-06-17 09:02


NVD link : CVE-2025-26909

Mitre link : CVE-2025-26909

CVE.ORG link : CVE-2025-26909


JSON object : View

Products Affected

wpplugins

  • hide_my_wp_ghost
CWE
CWE-98

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')