Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2025-49367
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-49367 is a PHP Local File Inclusion (LFI) vulnerability in the AncoraThemes Monyxi WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Monyxi theme up to and including 1.1.8. The vulnerability was disclosed on December 18, 2025, and was reported by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High), exploitable remotely without authentication or user interaction, though with high attack complexity (Feedly, Patchstack).

Technical details

The root cause is improper control of filename parameters used in PHP include/require statements within the Monyxi WordPress theme (CWE-98). An attacker can manipulate file path inputs to cause the application to include arbitrary local files from the server's filesystem, potentially exposing sensitive configuration files or enabling PHP code execution if attacker-controlled content exists on the server. The vulnerability is network-exploitable without privileges or user interaction, though high attack complexity suggests specific conditions or non-default configurations must be met. No public proof-of-concept or detailed technical write-up has been published as of the disclosure date (Feedly, Patchstack).

Impact

Successful exploitation could allow an attacker to read sensitive local files on the server (e.g., wp-config.php containing database credentials), execute arbitrary PHP code under certain conditions, and fully compromise the confidentiality, integrity, and availability of the affected WordPress site. The CVSS score reflects high impact across all three pillars — confidentiality, integrity, and availability — making this a significant risk for sites running the vulnerable theme. Lateral movement within the hosting environment or access to other hosted sites on shared infrastructure is also a potential consequence (Feedly).

Exploitability

As of the disclosure date, there is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability has an EPSS score of approximately 0.053%, indicating a low current probability of exploitation in the near term. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly).

Mitigation and workarounds

The primary remediation is to update the Monyxi WordPress theme to a version beyond 1.1.8. As interim mitigations, administrators should implement strict input validation for any file inclusion mechanisms, use allowlists to restrict permitted file paths, and disable PHP functions that enable remote or dynamic file inclusion (e.g., via php.ini settings such as allow_url_include = Off). A thorough security audit of the WordPress environment is also recommended (Feedly, Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86801HIGH8.8
  • todo-lists-for-membership-sites
NoNoSep 17, 2026
CVE-2026-87963HIGH8.6
  • yo
NoNoSep 17, 2026
CVE-2026-91016MEDIUM5.3
  • motors-car-dealership-classified-listings
NoYesSep 17, 2026
CVE-2026-91019MEDIUM4.9
  • mage-eventpress
NoYesSep 17, 2026
CVE-2026-91017LOW3.7
  • robokassa
NoYesSep 17, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management