
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-49368 is a PHP Local File Inclusion (LFI) vulnerability in the AncoraThemes Palladio WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Palladio theme up to and including 1.1.10, allowing unauthenticated remote attackers to manipulate file inclusion paths. The vulnerability was published on December 18, 2025, and was reported by Patchstack. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).
The root cause is improper control of filenames used in PHP include/require statements within the Palladio theme (CWE-98), which is categorized under the broader CAPEC-193 (PHP Remote File Inclusion) attack pattern. An unauthenticated attacker can send a crafted network request that manipulates the filename parameter passed to a PHP file inclusion function, causing the application to include arbitrary local files from the server's filesystem. Exploitation requires high attack complexity (AC:H), suggesting some precondition such as specific server configuration or parameter guessing, but no authentication or user interaction is needed (Feedly).
Successful exploitation can result in high impacts to confidentiality, integrity, and availability of the affected WordPress installation. An attacker could read sensitive server-side files such as WordPress configuration files (wp-config.php) containing database credentials, potentially enabling further compromise including database access and lateral movement. In certain server configurations, LFI vulnerabilities can be chained with log poisoning or other techniques to achieve arbitrary code execution (Feedly).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
/wp-content/themes/palladio/style.css) or using tools like WPScan.include() or require() without proper sanitization.../../../../wp-config.php or /etc/passwd).../, ..%2F, %2e%2e%2f) in query parameters.wp-config.php, /etc/passwd, or PHP session files as reflected in server access logs.The primary remediation is to update the Palladio WordPress theme to a version beyond 1.1.10 as soon as a patched release is available from AncoraThemes. As interim workarounds, administrators should implement strict input validation for any file inclusion paths, use allowlist-based file inclusion mechanisms, and restrict web server filesystem permissions to limit accessible paths. Additionally, monitoring web application logs for path traversal patterns and conducting regular audits of installed WordPress themes and plugins are recommended (Feedly, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."