CVE-2025-60049
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60049 is a PHP Local File Inclusion (LFI) vulnerability in the axiomthemes Soleil WordPress theme, caused by improper control of filenames in PHP include/require statements. It affects all versions of the Soleil theme through 1.17. The vulnerability was reported by researcher "Bonds" on July 20, 2025, and published by Patchstack on August 19, 2025. It carries a CVSS v3.1 base score of 8.1 (High), exploitable by unauthenticated remote attackers with no user interaction required (Patchstack).

Technical details

The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is insufficiently validated before being passed to PHP's include or require statements within the Soleil theme. This allows an attacker to manipulate the filename parameter to reference arbitrary local files on the server. Exploitation requires no authentication and no user interaction, though the high attack complexity (AC:H) suggests some precondition or bypass technique may be needed. The vulnerability is categorized under OWASP Top 10 A3: Injection and CAPEC-193 (PHP Remote File Inclusion) (Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to include and read arbitrary local files from the server, potentially exposing sensitive configuration files such as WordPress wp-config.php (containing database credentials), /etc/passwd, or other server-side files. This can lead to complete database takeover, credential theft, and depending on server configuration, may enable arbitrary code execution. The vulnerability has high impact across confidentiality, integrity, and availability (Patchstack).

Exploitability

There is no public proof-of-concept exploit code available, and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).

Mitigation and workarounds

As of the time of publication, no official patch from the theme developer (axiomthemes) is available for the Soleil theme. Users should upgrade to a version beyond 1.17 if and when a patched release becomes available. In the interim, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts. Additional recommended mitigations include restricting network access to the affected WordPress installation, deploying Web Application Firewall (WAF) rules to block suspicious file inclusion requests, and contacting your hosting provider for assistance if immediate remediation is not possible (Patchstack).

Community reactions

Patchstack, which discovered and disclosed the vulnerability, classifies it as high priority and warns that LFI vulnerabilities of this type are frequently leveraged in mass-exploit campaigns against WordPress sites regardless of their traffic or popularity. No additional notable vendor statements, researcher commentary, or significant media coverage has been identified at this time (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16974MEDIUM6.4
  • kirki
NoYesAug 11, 2026
CVE-2026-14549NONEN/A
  • lingotek-translation
NoNoAug 11, 2026
CVE-2026-14548NONEN/A
  • lingotek-translation
NoNoAug 11, 2026
CVE-2026-19089NONEN/A
  • product-input-fields-for-woocommerce
NoYesAug 10, 2026
CVE-2026-19077NONEN/A
  • copy-delete-posts
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management