
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60063 is a Local File Inclusion (LFI) vulnerability in the Rosalinda WordPress theme developed by axiomthemes, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Rosalinda theme up to and including 1.2.3. The vulnerability was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on July 5, 2025, and published by Patchstack on August 4, 2025. It carries a CVSS v3.1 base score of 8.1 (High) (Patchstack).
The vulnerability stems from improper control of filenames used in PHP include/require statements within the Rosalinda WordPress theme (CWE-98), which allows an attacker to manipulate file path parameters to include arbitrary local files from the server. Exploitation requires no authentication or user interaction, though attack complexity is rated High, suggesting some precondition or constraint must be met (e.g., specific server configuration or parameter guessing). A successful attack can cause the server to read and output the contents of sensitive local files. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows a remote, unauthenticated attacker to read arbitrary local files from the web server, potentially exposing sensitive data such as WordPress configuration files (wp-config.php) containing database credentials, system files, and other confidential information. This could lead to complete database takeover, credential theft, and further lateral movement within the hosting environment. The vulnerability has high impact on confidentiality, integrity, and availability of the affected system (Patchstack).
As of the time of publication, there is no known public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution has been made, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies this as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites regardless of traffic or popularity (Patchstack).
include/require statement).../../../../wp-config.php or /etc/passwd).../, ..%2F, %2e%2e%2f) in query parameters; requests targeting sensitive files such as wp-config.php or /etc/passwd.wp-config.php disclosure.As of the publication date, no official patch from the theme developer (axiomthemes) is available for the Rosalinda theme beyond version 1.2.3. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators should consider deactivating and replacing the Rosalinda theme if a patched version is unavailable, implementing Web Application Firewall (WAF) rules to block path traversal attempts, and restricting network-level access to the WordPress installation where possible. Monitoring server logs for suspicious file inclusion attempts is also recommended (Patchstack).
The vulnerability was disclosed by Patchstack, which assigned it a high priority rating and noted its potential for use in mass-exploit campaigns targeting WordPress sites. The discovery is credited to Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity. No significant broader media coverage or notable researcher commentary beyond the Patchstack advisory has been identified at this time (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."