
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-52768 is a Local File Inclusion (LFI) vulnerability in the AncoraThemes Faith & Hope WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the theme up to and including 2.13.0, and was discovered by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity), reported on August 5, 2025, and published on September 4, 2025. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The root cause is improper control of filename parameters passed to PHP include/require statements within the Faith & Hope theme (CWE-98), which allows an attacker to manipulate file path inputs and cause the server to include arbitrary local files. The attack vector is network-based, requires no authentication and no user interaction, but has high attack complexity. An unauthenticated remote attacker can craft a malicious HTTP request with a manipulated filename parameter to trigger inclusion of sensitive local PHP files, potentially leading to code execution if writable or uploadable files are leveraged (Patchstack).
Successful exploitation can result in high confidentiality, integrity, and availability impact on the affected WordPress installation. An attacker could read sensitive server files (e.g., wp-config.php, /etc/passwd) exposing database credentials and system information, execute arbitrary PHP code if combined with a file upload or log poisoning technique, and potentially achieve full database or server compromise. Privilege escalation and lateral movement within the hosting environment are also plausible outcomes (Patchstack).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has classified it as high priority, noting that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).
../../../../wp-config.php or /etc/passwd).../, ..%2F, ....//) in query parameters or POST body targeting WordPress theme endpoints.wp-config.php, passwd, .env) in parameter values.wp-content/uploads/).www-data) executing shell commands or making outbound network connections.The primary remediation is to upgrade the Faith & Hope WordPress theme to a version beyond 2.13.0; however, as of the disclosure date, no official patch from the developer was available. Patchstack has issued a virtual patch (mitigation rule) for Patchstack-protected sites to block exploitation attempts until an official fix is released. As interim workarounds, administrators should implement strict input validation for file inclusion parameters, use allowlists for permitted file paths, deploy a Web Application Firewall (WAF) with LFI detection rules, and restrict file system access for the web server user (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."