
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60049 is a PHP Local File Inclusion (LFI) vulnerability in the axiomthemes Soleil WordPress theme, caused by improper control of filenames in PHP include/require statements. It affects all versions of the Soleil theme through 1.17. The vulnerability was reported by researcher "Bonds" on July 20, 2025, and published by Patchstack on August 19, 2025. It carries a CVSS v3.1 base score of 8.1 (High), exploitable by unauthenticated remote attackers with no user interaction required (Patchstack).
The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is insufficiently validated before being passed to PHP's include or require statements within the Soleil theme. This allows an attacker to manipulate the filename parameter to reference arbitrary local files on the server. Exploitation requires no authentication and no user interaction, though the high attack complexity (AC:H) suggests some precondition or bypass technique may be needed. The vulnerability is categorized under OWASP Top 10 A3: Injection and CAPEC-193 (PHP Remote File Inclusion) (Patchstack).
Successful exploitation allows an unauthenticated attacker to include and read arbitrary local files from the server, potentially exposing sensitive configuration files such as WordPress wp-config.php (containing database credentials), /etc/passwd, or other server-side files. This can lead to complete database takeover, credential theft, and depending on server configuration, may enable arbitrary code execution. The vulnerability has high impact across confidentiality, integrity, and availability (Patchstack).
There is no public proof-of-concept exploit code available, and no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).
As of the time of publication, no official patch from the theme developer (axiomthemes) is available for the Soleil theme. Users should upgrade to a version beyond 1.17 if and when a patched release becomes available. In the interim, Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts. Additional recommended mitigations include restricting network access to the affected WordPress installation, deploying Web Application Firewall (WAF) rules to block suspicious file inclusion requests, and contacting your hosting provider for assistance if immediate remediation is not possible (Patchstack).
Patchstack, which discovered and disclosed the vulnerability, classifies it as high priority and warns that LFI vulnerabilities of this type are frequently leveraged in mass-exploit campaigns against WordPress sites regardless of their traffic or popularity. No additional notable vendor statements, researcher commentary, or significant media coverage has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."