CVE-2025-12549: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-12549 is a Local File Inclusion (LFI) vulnerability in the Rozy - Flower Shop WordPress theme developed by magentech. It stems from improper control of filename parameters used in PHP include/require statements (CWE-98), allowing unauthenticated remote attackers to include and execute arbitrary local files on the server. All versions of the theme through 1.2.25 are affected. The vulnerability was reported on August 6, 2025, by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and published by Patchstack on January 7–8, 2026. The CNA (Patchstack) assigned a CVSS v3.1 base score of 8.1 (High) (Patchstack Advisory).

Technical details

The root cause is classified under CWE-98 — Improper Control of Filename for Include/Require Statement in PHP Program. The Rozy - Flower Shop theme fails to properly validate or sanitize user-supplied input before passing it to PHP include or require statements, enabling an attacker to manipulate the filename parameter to reference arbitrary files on the server's filesystem. Because no authentication or user interaction is required, the attack can be launched remotely over the network with low complexity. This class of vulnerability is associated with CAPEC-193 (PHP Remote File Inclusion) and is commonly exploited to read sensitive files (e.g., wp-config.php) or chain with file upload vulnerabilities to achieve remote code execution (Patchstack Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to include and render arbitrary local files from the server, potentially exposing sensitive credentials such as WordPress database credentials stored in wp-config.php, leading to full database compromise. The vulnerability carries high impact across confidentiality (unauthorized file and source code access), integrity (potential arbitrary code execution via log poisoning or uploaded file inclusion), and availability (resource exhaustion or system destabilization). Given the unauthenticated, network-accessible nature of the flaw, it is suitable for mass-exploit campaigns targeting WordPress sites at scale (Patchstack Advisory).

Exploitability

As of the time of reporting, no public proof-of-concept exploit code has been identified, and there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.115%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies this as high priority, noting that vulnerabilities of this class are frequently used in mass-exploit campaigns against WordPress sites regardless of their traffic or popularity (Patchstack Advisory).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Rozy - Flower Shop theme (version ≤ 1.2.25) using tools like WPScan, Shodan, or Google dorks (e.g., inurl:wp-content/themes/rozy).
  2. Identify vulnerable parameter: Analyze the theme's PHP source code or HTTP responses to locate the endpoint and parameter that is passed unsanitized to a PHP include or require statement.
  3. Craft malicious request: Send an HTTP request (GET or POST) to the vulnerable endpoint with a manipulated filename parameter pointing to a sensitive local file, e.g., ../../../../wp-config.php or /etc/passwd.
  4. Extract sensitive data: Review the server's response for the contents of the included file, which may contain database credentials, secret keys, or other sensitive configuration data.
  5. Escalate (optional): If file upload is possible (e.g., via media upload), upload a PHP web shell and use the LFI to include and execute it, achieving remote code execution on the server (Patchstack Advisory).

Indicators of compromise

  • Network: Unusual HTTP requests to theme-related endpoints containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters or POST body; requests referencing sensitive files such as wp-config.php, passwd, or server log files.
  • Logs: WordPress or web server access logs showing repeated requests to Rozy theme PHP files with suspicious filename parameters; HTTP 200 responses to requests containing traversal patterns.
  • File System: Unexpected PHP files or web shells uploaded to the WordPress media or theme directories; modification timestamps on theme files inconsistent with legitimate updates.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget) that may indicate successful code execution following LFI chaining.

Mitigation and workarounds

As of the disclosure date, no official patch from magentech is available for the Rozy - Flower Shop theme. Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until an official fix is released. Recommended actions include: (1) Remove or replace the theme if a patched version is unavailable; (2) Deploy a Web Application Firewall (WAF) with rules to detect and block path traversal and LFI patterns; (3) Set allow_url_include = Off in php.ini to reduce attack surface (note: this does not prevent LFI, only RFI); (4) Audit file permissions and restrict web server access to sensitive files; (5) Monitor web server logs for traversal patterns. Contact magentech directly for patch availability and timeline (Patchstack Advisory).

Community reactions

Wordfence included CVE-2025-12549 in its weekly WordPress vulnerability intelligence report covering January 5–11, 2026, highlighting it as part of a broader set of newly disclosed WordPress theme and plugin vulnerabilities (Wordfence Blog). Patchstack, the assigning CNA, classified the vulnerability as high priority and noted its potential for use in mass-exploit campaigns. No significant independent researcher commentary or broader media coverage has been identified beyond these vendor-level reports.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management