
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60043 is a PHP Local File Inclusion (LFI) vulnerability in the Wanderic WordPress theme developed by AncoraThemes. It affects all versions of the theme up to and including 1.0.10, with no official patch currently available. The vulnerability was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on July 24, 2025, and published by Patchstack on August 23, 2025. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The vulnerability is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), which enables PHP Local File Inclusion. The flaw arises from insufficient validation of user-supplied input used in PHP include or require statements within the theme, allowing an attacker to manipulate file path parameters to include arbitrary local files. Exploitation requires no authentication but does require user interaction (e.g., a victim visiting a crafted URL), and is network-accessible with low attack complexity (Patchstack).
Successful exploitation allows an attacker to read arbitrary local files on the server, including sensitive configuration files such as WordPress wp-config.php, which contains database credentials. This can lead to complete database takeover, exposure of API keys or secrets, and potential code execution if the attacker can include a file containing PHP code (e.g., via log poisoning or uploaded files). The vulnerability has high confidentiality and integrity impact, with no availability impact per the CVSS scoring (Patchstack).
No public proof-of-concept exploit code has been observed, and there is no evidence of active in-the-wild exploitation at this time. The vulnerability requires no authentication, making it accessible to any network attacker, though user interaction is required. The EPSS score is approximately 0.053% (0.000530), indicating a currently low probability of exploitation in the near term. It is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).
../../../../wp-config.php) into the vulnerable parameter to reference a sensitive local file.wp-config.php) in the HTTP response.../, ..%2F, %2e%2e%2f) in query parameters; unusual GET/POST requests referencing system files like wp-config.php, /etc/passwd, or PHP log files.wp-config.php or /etc/passwd; presence of web shells in the uploads directory if LFI is chained with file upload.As of the publication date, no official patch from AncoraThemes is available for the Wanderic theme. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators should consider removing or replacing the Wanderic theme if a patched version is not available, implementing a Web Application Firewall (WAF) with LFI detection rules, and restricting PHP file inclusion via php.ini settings (e.g., allow_url_include = Off). Input validation for file paths and use of allowlists for permitted file inclusions are also recommended defensive measures (Patchstack).
The vulnerability was discovered and disclosed through Patchstack's Vulnerability Disclosure Program (VDP) by researcher Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity. Patchstack has classified it as high priority and noted that LFI vulnerabilities of this type are frequently leveraged in mass-exploit campaigns against WordPress sites. No significant broader media coverage or notable social media discussion has been observed beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."