
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12549 is a Local File Inclusion (LFI) vulnerability in the Rozy - Flower Shop WordPress theme developed by magentech. It stems from improper control of filename parameters used in PHP include/require statements (CWE-98), allowing unauthenticated remote attackers to include and execute arbitrary local files on the server. All versions of the theme through 1.2.25 are affected. The vulnerability was reported on August 6, 2025, by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and published by Patchstack on January 7–8, 2026. The CNA (Patchstack) assigned a CVSS v3.1 base score of 8.1 (High) (Patchstack Advisory).
The root cause is classified under CWE-98 — Improper Control of Filename for Include/Require Statement in PHP Program. The Rozy - Flower Shop theme fails to properly validate or sanitize user-supplied input before passing it to PHP include or require statements, enabling an attacker to manipulate the filename parameter to reference arbitrary files on the server's filesystem. Because no authentication or user interaction is required, the attack can be launched remotely over the network with low complexity. This class of vulnerability is associated with CAPEC-193 (PHP Remote File Inclusion) and is commonly exploited to read sensitive files (e.g., wp-config.php) or chain with file upload vulnerabilities to achieve remote code execution (Patchstack Advisory).
Successful exploitation allows an unauthenticated attacker to include and render arbitrary local files from the server, potentially exposing sensitive credentials such as WordPress database credentials stored in wp-config.php, leading to full database compromise. The vulnerability carries high impact across confidentiality (unauthorized file and source code access), integrity (potential arbitrary code execution via log poisoning or uploaded file inclusion), and availability (resource exhaustion or system destabilization). Given the unauthenticated, network-accessible nature of the flaw, it is suitable for mass-exploit campaigns targeting WordPress sites at scale (Patchstack Advisory).
As of the time of reporting, no public proof-of-concept exploit code has been identified, and there is no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.115%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies this as high priority, noting that vulnerabilities of this class are frequently used in mass-exploit campaigns against WordPress sites regardless of their traffic or popularity (Patchstack Advisory).
inurl:wp-content/themes/rozy).include or require statement.../../../../wp-config.php or /etc/passwd.../, ..%2F, %2e%2e%2f) in query parameters or POST body; requests referencing sensitive files such as wp-config.php, passwd, or server log files.bash, curl, wget) that may indicate successful code execution following LFI chaining.As of the disclosure date, no official patch from magentech is available for the Rozy - Flower Shop theme. Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until an official fix is released. Recommended actions include: (1) Remove or replace the theme if a patched version is unavailable; (2) Deploy a Web Application Firewall (WAF) with rules to detect and block path traversal and LFI patterns; (3) Set allow_url_include = Off in php.ini to reduce attack surface (note: this does not prevent LFI, only RFI); (4) Audit file permissions and restrict web server access to sensitive files; (5) Monitor web server logs for traversal patterns. Contact magentech directly for patch availability and timeline (Patchstack Advisory).
Wordfence included CVE-2025-12549 in its weekly WordPress vulnerability intelligence report covering January 5–11, 2026, highlighting it as part of a broader set of newly disclosed WordPress theme and plugin vulnerabilities (Wordfence Blog). Patchstack, the assigning CNA, classified the vulnerability as high priority and noted its potential for use in mass-exploit campaigns. No significant independent researcher commentary or broader media coverage has been identified beyond these vendor-level reports.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."