John Darrel Hide My WP Ghost
cpe:2.3:a:wpplugins:hide_my_wp_ghost:*:*:*:*:wordpress:*:*
- <= 5.4.01
A local file inclusion vulnerability has been identified in the Hide My WP Ghost WordPress plugin, specifically in versions through 5.4.01. This vulnerability arises from improper control of filenames in include or require statements, allowing for PHP remote file inclusion. Exploitation of this issue could lead to remote code execution.
Exploitation of this vulnerability could allow a malicious actor to include local files from the target website and execute them, potentially leading to a complete takeover of the website's database, depending on the configuration.
Users of the Hide My WP Ghost WordPress plugin should update to version 5.4.02 or later. Patchstack users can enable auto-updates for vulnerable plugins.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.