WordPress security plugin WP Ghost vulnerable to remote code execution bug
ID: d8d089dd-40fe-5b3f-9248-3db63ba2f618
STIX ID: report--d8d089dd-40fe-5b3f-9248-3db63ba2f618
Feed Name: Bleeping Computer
Threat Score
**Executive summary:** WP Ghost (versions up to 5.4.01) contains a critical LFI vulnerability (CVE-2025-26909, CVSS 9.6) that can allow unauthenticated attackers to include arbitrary files and, depending on server configuration, achieve remote code execution; Patchstack disclosed the issue and the vendor released patches in 5.4.02/5.4.03 — administrators should update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
