logo

WordPress security plugin WP Ghost vulnerable to remote code execution bug

ID: d8d089dd-40fe-5b3f-9248-3db63ba2f618

STIX ID: report--d8d089dd-40fe-5b3f-9248-3db63ba2f618

Feed Name: Bleeping Computer

Threat Score
72/100

Date Published: 2025-03-20

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

**Executive summary:** WP Ghost (versions up to 5.4.01) contains a critical LFI vulnerability (CVE-2025-26909, CVSS 9.6) that can allow unauthenticated attackers to include arbitrary files and, depending on server configuration, achieve remote code execution; Patchstack disclosed the issue and the vendor released patches in 5.4.02/5.4.03 — administrators should update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.