Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6427 | The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it possible for unauthenticated attackers to read the contents of specific file types on the server, which can contain sensitive information. |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Fri, 20 Jun 2025 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpplugins
Wpplugins hide My Wp Ghost |
|
| CPEs | cpe:2.3:a:wpplugins:hide_my_wp_ghost:*:*:*:*:*:wordpress:*:* | |
| Vendors & Products |
Wpplugins
Wpplugins hide My Wp Ghost |
Fri, 14 Mar 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 14 Mar 2025 04:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The WP Ghost (Hide My WP Ghost) – Security & Firewall plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 5.4.01 via the showFile function. This makes it possible for unauthenticated attackers to read the contents of specific file types on the server, which can contain sensitive information. | |
| Title | WP Ghost <= 5.4.01 - Unauthenticated Limited File Read | |
| Weaknesses | CWE-23 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2025-03-14T13:45:48.661Z
Reserved: 2025-03-06T15:06:51.356Z
Link: CVE-2025-2056
Updated: 2025-03-14T13:45:36.584Z
Status : Analyzed
Published: 2025-03-14T05:15:42.523
Modified: 2025-06-20T18:13:13.507
Link: CVE-2025-2056
No data.
OpenCVE Enrichment
No data.
EUVD