CVE-2025-8009: Cleverplugins Security Ninja – WordPress Security Plugin & Firewall

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get_file_source' function. This makes it possible for authenticated attackers, with Administrator-level access and above, to extract sensitive data, including the contents of any file on the server.

Affected products

  • Cleverplugins Security Ninja – WordPress Security Plugin & Firewall: from 5.201, up to and including 5.242

Published 2025-07-24. Last modified 2026-06-17.