Arbitrary File Read Vulnerability in Security Ninja WordPress Plugin
CVE-2025-8009

4.9MEDIUM

What is CVE-2025-8009?

The Security Ninja plugin for WordPress suffers from an Arbitrary File Read vulnerability due to a flaw in the 'get_file_source' function. This issue allows authenticated attackers with Administrator-level access or higher to retrieve sensitive files stored on the server, potentially exposing critical data. It is essential for users of the Security Ninja plugin to ensure that they are using the latest version to mitigate this vulnerability.

Affected Version(s)

Security Ninja – WordPress Security Plugin & Firewall 5.201 <= 5.242

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jonas Benjamin Friedli
.