
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-58931 is a Local File Inclusion (LFI) vulnerability in the Palatio WordPress theme developed by axiomthemes, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Palatio theme through and including version 1.6, and can be exploited by unauthenticated remote attackers over the network. The vulnerability was reported by researcher "Bonds" on July 23, 2025, and published by Patchstack on August 22, 2025. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The root cause is improper control of filename parameters used in PHP include/require statements within the Palatio theme (CWE-98), which allows an attacker to manipulate file path inputs to include arbitrary local files on the server. Because no authentication or user interaction is required, an unauthenticated remote attacker can send a crafted HTTP request with a malicious filename parameter to trigger the inclusion of sensitive local files. The attack complexity is rated High, suggesting some precondition or specific condition must be met (e.g., specific server configuration or parameter guessing), but no privileges are needed. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an attacker to include and render arbitrary local files from the server, potentially exposing sensitive data such as WordPress configuration files (wp-config.php), database credentials, application source code, and system files. Access to database credentials could enable complete database takeover, while exposure of other configuration data could facilitate further lateral movement or privilege escalation within the hosting environment. The confidentiality, integrity, and availability impacts are all rated High in the CVSS scoring (Patchstack).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack rates this as high priority, noting that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites regardless of their traffic or popularity (Patchstack).
inurl:wp-content/themes/palatio).template, file, or page parameter in theme functions).../../../../wp-config.php or /etc/passwd).wp-config.php) to access the database directly, create admin accounts, or pivot to further compromise the hosting environment (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters; repeated requests to theme PHP files with varying file path values.wp-config.php, /etc/passwd, or PHP session files coinciding with suspicious web requests.As of the Patchstack advisory, no official patch from the theme developer (axiomthemes) is available for the Palatio theme. Organizations should upgrade to a version above 1.6 if one becomes available, or consider replacing the theme with a supported alternative. Patchstack has issued a virtual patching/mitigation rule for its users to block exploitation attempts in the interim. Additional mitigations include deploying a Web Application Firewall (WAF) to detect and block path traversal and file inclusion attempts, restricting PHP file permissions, disabling dangerous PHP functions (e.g., allow_url_include), and reviewing server access logs for signs of exploitation (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher "Bonds," has classified it as high priority and noted that LFI vulnerabilities of this type are frequently leveraged in mass-exploit campaigns against WordPress sites. No significant vendor statements from axiomthemes, broader media coverage, or notable researcher commentary beyond the Patchstack advisory have been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."