The WordPress plugin WP Ghost is vulnerable to a critical vulnerability, which could be exploited by unauthorized attackers to remotely execute code and compromise servers.

WP Ghost is a popular security plugin used on over 200,000 WordPress websites and claims to prevent 140,000 hacking attacks and over 9 million brute-forcing attempts every month.
See also: 'DollyWay' malware campaign compromised 20,000 WordPress sites
In addition, it provides protection against various security attacks, such as:
• SQL injection
• script injection
• vulnerability exploitation
• malware installation
• file inclusion exploits
• directory traversal attacks
• cross-site scripting (XSS)
However, according to evidence uncovered by Patchstack, the plugin contains a critical remote code execution, with a CVSS score of 9.6, which could allow an attacker to gain complete control of a website.
The vulnerability, tracked as CVE-2025-26909, affects all versions of WP Ghost up to and including 5.4.01. The root of the issue is insufficient input validation in the 'showFile()' function. If an attacker exploits this vulnerability, they could include arbitrary files via modified URL paths, which could lead to a complete compromise of the website.
See also: Vulnerability in Chaty Pro plugin puts WordPress sites at risk
It’s worth noting that the vulnerability is only triggered if the WP Ghost plugin’s “ Change Paths ” feature is set to Lite or Ghost mode . While these features are not enabled by default, Patchstack says that Local File Inclusion (LFI) applies to almost all settings.
“Due to the behavior of the LFI case, this vulnerability could lead to remote code execution in almost all environment settings“.
Therefore, the vulnerability allows LFI globally, but whether it will escalate to RCE depends on the server configuration.
An LFI vulnerability can be dangerous even if it does not escalate to remote code execution. For example, it could allow access source code, and denial of service (DoS) attacks.
The vulnerability in the WordPress plugin WP Ghost was discovered by researcher Dimas Maulana on February 25, 2025. Patchstack analyzed it internally and eventually notified the vendor on March 3. The next day, a fix, which was incorporated into version 5.4.02 of WP Ghost, while version 5.4.03 has also become available in the meantime. Users are advised to upgrade to protect themselves from this critical vulnerability.
See also: WP3.XYZ malware: Adds fraudulent administrators to 5,000+ WordPress sites
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

WordPress Security
WordPress website security requires a multi-pronged approach to protect against potential threats. One key strategy includes regularly updating plugins and themes to ensure that any security vulnerabilities have been patched. Using strong passwords and enabling two-factor authentication adds an extra layer of security. Additionally, regularly backing up your website can protect your data in the event of an attack.
It is also recommended to install a powerful security plugin that offers features such as firewall protection, malware , and brute force attack prevention.
Importance of WordPress protection
Protecting WordPress websites is especially important for many reasons. First, WordPress websites are very popular, which means they are a prime target for cybercriminals. If your website is not protected, significant damage can occur.
Additionally, an unsecured WordPress site can undermine the trust and credibility you’ve built with customers your. If their data is compromised, they’re more likely to sue you and switch to other companies.
Source: www.bleepingcomputer.com
