Arbitrary File Read Vulnerability in Security Ninja WordPress Plugin
CVE-2025-8009
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2025
What is CVE-2025-8009?
The Security Ninja plugin for WordPress suffers from an Arbitrary File Read vulnerability due to a flaw in the 'get_file_source' function. This issue allows authenticated attackers with Administrator-level access or higher to retrieve sensitive files stored on the server, potentially exposing critical data. It is essential for users of the Security Ninja plugin to ensure that they are using the latest version to mitigate this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Security Ninja β WordPress Security Plugin & Firewall 5.201 <= 5.242
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jonas Benjamin Friedli