
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-53429 is a PHP Local File Inclusion (LFI) vulnerability in the AncoraThemes Exit Game WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement). It affects all versions of the Exit Game theme up to and including 1.4.3, and can be exploited by unauthenticated remote attackers. The vulnerability was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on August 5, 2025, and published by Patchstack on September 4, 2025. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The root cause is improper control of filenames used in PHP include/require statements within the Exit Game theme (CWE-98), which falls under the OWASP Top 10 category A3: Injection. An unauthenticated attacker can send a crafted network request that manipulates a file path parameter, causing the PHP application to include arbitrary local files from the server's filesystem. No authentication or user interaction is required, though the attack complexity is rated High, suggesting some precondition or bypass is needed to reliably trigger the inclusion. No public proof-of-concept code has been disclosed as of the time of publication (Patchstack).
Successful exploitation allows an attacker to read sensitive local files on the server, such as WordPress configuration files (wp-config.php) containing database credentials, which could lead to complete database takeover. Beyond credential theft, depending on server configuration, LFI can be chained with other techniques (e.g., log poisoning) to achieve arbitrary code execution on the server. The vulnerability impacts confidentiality, integrity, and availability — all rated High in the CVSS scoring — and could result in full compromise of the affected WordPress site and its underlying infrastructure (Patchstack).
As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
As of the publication date, no official patch from the theme developer (AncoraThemes) is available for Exit Game versions ≤ 1.4.3. Site owners should monitor for an updated theme release and apply it immediately when available. In the interim, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts. Additional hardening steps include implementing strict input validation for file inclusion parameters, using allowlists for permitted file paths, applying the principle of least privilege to the web server process, and auditing the WordPress site for signs of unauthorized file access (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."