CVE-2025-52768: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-52768 is a Local File Inclusion (LFI) vulnerability in the AncoraThemes Faith & Hope WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the theme up to and including 2.13.0, and was discovered by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity), reported on August 5, 2025, and published on September 4, 2025. The vulnerability carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).

Technical details

The root cause is improper control of filename parameters passed to PHP include/require statements within the Faith & Hope theme (CWE-98), which allows an attacker to manipulate file path inputs and cause the server to include arbitrary local files. The attack vector is network-based, requires no authentication and no user interaction, but has high attack complexity. An unauthenticated remote attacker can craft a malicious HTTP request with a manipulated filename parameter to trigger inclusion of sensitive local PHP files, potentially leading to code execution if writable or uploadable files are leveraged (Patchstack).

Impact

Successful exploitation can result in high confidentiality, integrity, and availability impact on the affected WordPress installation. An attacker could read sensitive server files (e.g., wp-config.php, /etc/passwd) exposing database credentials and system information, execute arbitrary PHP code if combined with a file upload or log poisoning technique, and potentially achieve full database or server compromise. Privilege escalation and lateral movement within the hosting environment are also plausible outcomes (Patchstack).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a currently low probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has classified it as high priority, noting that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Faith & Hope theme (version ≤ 2.13.0) via passive fingerprinting tools (e.g., WPScan, Shodan) by detecting theme-specific assets in HTTP responses.
  2. Identify vulnerable parameter: Analyze the theme's PHP source or observed HTTP requests to locate the file inclusion parameter that accepts user-controlled input without sanitization.
  3. Craft malicious request: Send an unauthenticated HTTP GET or POST request to the vulnerable endpoint with a manipulated filename parameter pointing to a sensitive local file (e.g., ../../../../wp-config.php or /etc/passwd).
  4. Extract sensitive data: Review the server's HTTP response for the contents of the included file, which may expose database credentials, API keys, or system user information.
  5. Escalate (optional): If file upload functionality exists on the site, upload a PHP web shell, then use the LFI to include and execute it, achieving remote code execution (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests containing path traversal sequences (e.g., ../, ..%2F, ....//) in query parameters or POST body targeting WordPress theme endpoints.
  • Logs: WordPress or web server access logs showing requests with encoded traversal patterns or references to sensitive files (wp-config.php, passwd, .env) in parameter values.
  • File System: Unexpected PHP files or web shells uploaded to world-writable directories (e.g., wp-content/uploads/).
  • Process: Unusual PHP child processes spawned by the web server user (e.g., www-data) executing shell commands or making outbound network connections.

Mitigation and workarounds

The primary remediation is to upgrade the Faith & Hope WordPress theme to a version beyond 2.13.0; however, as of the disclosure date, no official patch from the developer was available. Patchstack has issued a virtual patch (mitigation rule) for Patchstack-protected sites to block exploitation attempts until an official fix is released. As interim workarounds, administrators should implement strict input validation for file inclusion parameters, use allowlists for permitted file paths, deploy a Web Application Firewall (WAF) with LFI detection rules, and restrict file system access for the web server user (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management