
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54003 is a PHP Local File Inclusion (LFI) vulnerability in the Mikado-Themes Depot WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Depot theme up to and including version 1.16. The vulnerability was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on September 9, 2025, and published by Patchstack on January 8, 2026. The CNA (Patchstack) assigned a CVSS v3.1 base score of 8.1 (High), while CISA-ADP initially scored it 9.8 (Critical) before that score was removed (Patchstack, NVD).
The root cause is improper sanitization of filename parameters passed to PHP include/require statements within the Depot WordPress theme (CWE-98). An unauthenticated remote attacker can manipulate these parameters to force the PHP interpreter to include arbitrary local files from the server's filesystem, exposing their contents. The attack requires no authentication, no user interaction, and is executable over the network with low complexity, though Patchstack's CVSS assessment rates attack complexity as High. No public proof-of-concept code has been identified at this time (Patchstack, NVD).
Successful exploitation allows an unauthenticated attacker to read arbitrary local files on the web server, including sensitive configuration files (e.g., wp-config.php containing database credentials), application source code, and system files such as /etc/passwd. Access to database credentials could enable complete database takeover, and exposure of application secrets could facilitate further compromise of the WordPress installation or underlying server. The vulnerability carries high impact to confidentiality, integrity, and availability (Patchstack).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
style.css files.include or require statement without adequate sanitization — typically via a URL query parameter or POST field.../../../../wp-config.php or /etc/passwd) in the vulnerable parameter to reference a target local file.../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.wp-config.php, /etc/passwd, or /etc/shadow by the web server process.No official patch from Mikado-Themes is currently available for the Depot theme. Patchstack has issued a virtual patching/mitigation rule for Patchstack-protected sites to block exploitation attempts until an official fix is released. Site owners should implement Web Application Firewall (WAF) rules to block known LFI patterns (path traversal sequences), enforce strict input validation on all filename parameters, and review access logs for suspicious inclusion attempts. If the theme cannot be replaced or patched, consider disabling it and switching to an alternative theme until a fix is available (Patchstack).
Wordfence included CVE-2025-54003 in its weekly WordPress vulnerability intelligence report covering January 5–11, 2026, highlighting it as part of broader WordPress theme security concerns. Patchstack, the discovering and reporting organization, classified it as high priority and noted the vulnerability class is commonly leveraged in mass-exploit campaigns against WordPress sites (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."