Arbitrary File Read Vulnerability in Security Ninja WordPress Plugin
CVE-2025-8009
4.9MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2025
What is CVE-2025-8009?
The Security Ninja plugin for WordPress suffers from an Arbitrary File Read vulnerability due to a flaw in the 'get_file_source' function. This issue allows authenticated attackers with Administrator-level access or higher to retrieve sensitive files stored on the server, potentially exposing critical data. It is essential for users of the Security Ninja plugin to ensure that they are using the latest version to mitigate this vulnerability.
Affected Version(s)
Security Ninja – WordPress Security Plugin & Firewall 5.201 <= 5.242