CVE-2025-2056

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Mar 14, 2025
CWE ID 23

Summary

CVE-2025-2056 is a vulnerability affecting the WP Ghost (Hide My WP Ghost) Security & Firewall plugin for WordPress. This issue, present in versions up to 5.4.01, allows unauthenticated attackers to perform Path Traversal attacks. Specifically, the showFile function is the point of entry, enabling adversaries to read the contents of certain file types on the server. The potential consequences of this exploit are significant, as these files may contain sensitive information that, if accessed, could lead to serious data breaches.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share