
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-54701 is a Local File Inclusion (LFI) vulnerability in the ThemeMove Unicamp WordPress theme that allows unauthenticated remote attackers to include and execute arbitrary server-side files. It affects all versions of the Unicamp theme up to and including 2.6.3, with version 2.6.4 containing the fix. The vulnerability was reported on July 15, 2025, by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) and publicly disclosed on August 14, 2025. It carries a CVSS v3.1 base score of 9.8 (Critical) per NVD, and 8.1 (High) per Patchstack (Patchstack, Red Hat CVE).
The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is passed unsanitized into PHP include or require statements within the Unicamp theme. This allows an attacker to manipulate the filename parameter to reference arbitrary files on the server's filesystem. Exploitation requires no authentication, no user interaction, and can be performed remotely over the network with low complexity, making it trivially exploitable against any unpatched installation (Patchstack, Red Hat CVE).
Successful exploitation allows an unauthenticated attacker to read sensitive server files — including WordPress configuration files such as wp-config.php containing database credentials — potentially enabling complete database takeover. Attackers may also execute arbitrary PHP code on the server, modify website content, and fully compromise the web application. The combination of high confidentiality, integrity, and availability impact with no privilege requirement makes this a severe threat to any site running the vulnerable theme (Patchstack).
No public proof-of-concept exploit code has been confirmed at this time, and there is no verified evidence of active in-the-wild exploitation. However, Patchstack has flagged this vulnerability as "Known to be exploited (KEV)" in their database and notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The EPSS score is approximately 0.0015 (0.15%), indicating currently low but non-negligible exploitation probability. No specific threat actor attribution has been reported (Patchstack).
/wp-content/themes/unicamp/).include or require statement, typically via a GET or POST parameter controlling a template or file path.../../../../wp-config.php or other files accessible to the web server process.wp-config.php.../, ..%2F, %2e%2e%2f) in parameters; requests to theme endpoints with unexpected file path values./wp-content/themes/unicamp/ endpoints with traversal patterns or references to sensitive files like wp-config.php; PHP error logs indicating failed file inclusion attempts.curl, wget, bash) indicating potential code execution following successful LFI exploitation (Patchstack).The primary remediation is to upgrade the ThemeMove Unicamp WordPress theme to version 2.6.4 or later, which contains the patch for this vulnerability. For sites where immediate patching is not feasible, implement network-level controls to restrict external access to vulnerable theme files, disable non-essential theme functionality, and monitor web server logs for suspicious file inclusion attempts. Patchstack users benefit from a virtual patching/mitigation rule that blocks exploitation attempts until the theme is updated (Patchstack).
The vulnerability was discovered and reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity and disclosed through Patchstack on August 14, 2025. Patchstack classified it as high priority and flagged it as likely to be used in mass-exploit campaigns. A Bluesky post referencing the CVE was noted in threat intelligence feeds shortly after disclosure, indicating some community awareness, though no major media coverage or notable researcher commentary beyond the initial Patchstack advisory has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."