
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49367 is a PHP Local File Inclusion (LFI) vulnerability in the AncoraThemes Monyxi WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Monyxi theme up to and including 1.1.8. The vulnerability was disclosed on December 18, 2025, and was reported by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High), exploitable remotely without authentication or user interaction, though with high attack complexity (Feedly, Patchstack).
The root cause is improper control of filename parameters used in PHP include/require statements within the Monyxi WordPress theme (CWE-98). An attacker can manipulate file path inputs to cause the application to include arbitrary local files from the server's filesystem, potentially exposing sensitive configuration files or enabling PHP code execution if attacker-controlled content exists on the server. The vulnerability is network-exploitable without privileges or user interaction, though high attack complexity suggests specific conditions or non-default configurations must be met. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Feedly, Patchstack).
Successful exploitation could allow an attacker to read sensitive local files on the server (e.g., wp-config.php containing database credentials), execute arbitrary PHP code under certain conditions, and fully compromise the confidentiality, integrity, and availability of the affected WordPress site. The CVSS score reflects high impact across all three pillars — confidentiality, integrity, and availability — making this a significant risk for sites running the vulnerable theme. Lateral movement within the hosting environment or access to other hosted sites on shared infrastructure is also a potential consequence (Feedly).
As of the disclosure date, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability has an EPSS score of approximately 0.053%, indicating a low current probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).
The primary remediation is to update the Monyxi WordPress theme to a version beyond 1.1.8. As interim mitigations, administrators should implement strict input validation for any file inclusion mechanisms, use allowlists to restrict permitted file paths, and disable PHP functions that enable remote or dynamic file inclusion (e.g., via php.ini settings such as allow_url_include = Off). A thorough security audit of the WordPress environment is also recommended (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."