
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-53448 is a PHP Local File Inclusion (LFI) vulnerability in the Axiomthemes Rally WordPress theme, affecting all versions up to and including 1.1. The flaw stems from improper control of filename for include/require statements in PHP (CWE-98), allowing unauthenticated remote attackers to include arbitrary local files on the server. The vulnerability was reported by researcher "Bonds" on August 3, 2025, and published by Patchstack on September 2, 2025. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The vulnerability is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), which occurs when user-supplied input is passed unsanitized to PHP file inclusion functions (include, require, etc.). An unauthenticated attacker can manipulate a filename parameter to traverse the server's file system and include arbitrary local files, potentially exposing their contents or triggering code execution if the included file contains PHP. The attack vector is network-based with high attack complexity and requires no privileges or user interaction, consistent with CAPEC-193 (PHP Remote File Inclusion) patterns (Patchstack).
Successful exploitation allows an attacker to read sensitive local files on the WordPress server, including configuration files such as wp-config.php that contain database credentials, potentially enabling complete database takeover. Depending on server configuration, the vulnerability may also facilitate arbitrary code execution if PHP-parseable files can be included. The confidentiality, integrity, and availability impacts are all rated High, indicating potential for full compromise of the affected WordPress site (Patchstack).
As of the time of publication, there is no known public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.00115 (low probability of near-term exploitation). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack).
style.css files.../../../../wp-config.php or ../../../../etc/passwd) in the vulnerable parameter to traverse the directory structure.wp-config.php, which can then be used for further compromise such as database access or privilege escalation (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters or POST body.wp-config.php, /etc/passwd, or other system files reflected in server-side file access logs.debug.log).As of the publication date, no official patch from Axiomthemes is available for the Rally theme. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site owners should update the Rally theme to any version beyond 1.1 if a patched release becomes available, or consider replacing the theme. In the interim, deploying a Web Application Firewall (WAF) with rules targeting path traversal and file inclusion patterns, restricting file permissions, and sanitizing all user-supplied input to file inclusion functions are recommended mitigations (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."