CVE-2025-60063
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60063 is a Local File Inclusion (LFI) vulnerability in the Rosalinda WordPress theme developed by axiomthemes, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Rosalinda theme up to and including 1.2.3. The vulnerability was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on July 5, 2025, and published by Patchstack on August 4, 2025. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).

Technical details

The vulnerability stems from improper control of filenames used in PHP include/require statements within the Rosalinda WordPress theme (CWE-98), which allows an attacker to manipulate file path parameters to include arbitrary local files from the server. Exploitation requires no authentication or user interaction, though attack complexity is rated High, suggesting some precondition or constraint must be met (e.g., specific server configuration or parameter guessing). A successful attack can cause the server to read and output the contents of sensitive local files. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows a remote, unauthenticated attacker to read arbitrary local files from the web server, potentially exposing sensitive data such as WordPress configuration files (wp-config.php) containing database credentials, system files, and other confidential information. This could lead to complete database takeover, credential theft, and further lateral movement within the hosting environment. The vulnerability has high impact on confidentiality, integrity, and availability of the affected system (Patchstack).

Exploitability

As of the time of publication, there is no known public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies this as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites regardless of traffic or popularity (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Rosalinda theme (version ≤ 1.2.3) via web crawlers, Shodan, WPScan, or similar tools by fingerprinting theme assets or metadata.
  2. Identify vulnerable parameter: Locate the theme's PHP file(s) that accept user-controlled input for file inclusion (e.g., a template or page parameter passed to an include/require statement).
  3. Craft malicious request: Send an unauthenticated HTTP request with a manipulated file path parameter designed to traverse directories and reference a sensitive local file (e.g., ../../../../wp-config.php or /etc/passwd).
  4. Retrieve sensitive data: If successful, the server returns the contents of the targeted file in the HTTP response, exposing credentials, configuration data, or other sensitive information.
  5. Escalate access: Use extracted database credentials or other secrets to gain further access to the WordPress database, admin panel, or underlying server (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP GET or POST requests to WordPress theme files containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters; requests targeting sensitive files such as wp-config.php or /etc/passwd.
  • Logs: Web server access logs showing requests with encoded or raw directory traversal patterns directed at Rosalinda theme endpoints; repeated 200 OK responses to requests with suspicious file path parameters.
  • File System: No direct file system artifacts expected from read-only LFI, but monitor for subsequent unauthorized file writes or web shell uploads if exploitation escalates.
  • Process: Unexpected database connection attempts from new or external IP addresses following potential credential exposure via wp-config.php disclosure.

Mitigation and workarounds

As of the publication date, no official patch from the theme developer (axiomthemes) is available for the Rosalinda theme beyond version 1.2.3. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators should consider deactivating and replacing the Rosalinda theme if a patched version is unavailable, implementing Web Application Firewall (WAF) rules to block path traversal attempts, and restricting network-level access to the WordPress installation where possible. Monitoring server logs for suspicious file inclusion attempts is also recommended (Patchstack).

Community reactions

The vulnerability was disclosed by Patchstack, which assigned it a high priority rating and noted its potential for use in mass-exploit campaigns targeting WordPress sites. The discovery is credited to Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity. No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified at this time (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-19089NONEN/A
  • product-input-fields-for-woocommerce
NoYesAug 10, 2026
CVE-2026-19077NONEN/A
  • copy-delete-posts
NoYesAug 10, 2026
CVE-2026-19075NONEN/A
  • all-in-one-video-gallery
NoYesAug 10, 2026
CVE-2026-19074NONEN/A
  • advanced-classifieds-and-directory-pro
NoYesAug 10, 2026
CVE-2026-19053NONEN/A
  • prosolution-wp-client
NoYesAug 10, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management