
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60069 is a PHP Local File Inclusion (LFI) vulnerability in the ThemeMove MinimogWP WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement). It affects all MinimogWP versions up to and including 3.9.6, and was reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity on July 3, 2025, with public disclosure by Patchstack on August 2, 2025. The vulnerability carries a CVSS v3.1 base score of 8.1 (High), exploitable remotely without authentication (Patchstack).
The root cause is improper control of filename parameters used in PHP include/require statements within the MinimogWP theme (CWE-98), which allows an attacker to manipulate file path inputs to include arbitrary local files. The attack vector is network-based, requires no authentication or user interaction, but has high attack complexity, suggesting some precondition or constraint must be met (e.g., specific server configuration or parameter guessing). Exploitation falls under OWASP Top 10 A3: Injection and CAPEC-193 (PHP Remote File Inclusion). No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an attacker to include and expose the contents of arbitrary local files on the web server, with high impacts to confidentiality, integrity, and availability. Sensitive files such as WordPress wp-config.php (containing database credentials) could be read, potentially enabling complete database takeover. Depending on server configuration, inclusion of attacker-controlled files (e.g., uploaded content) could escalate to remote code execution, fully compromising the affected WordPress site (Patchstack).
No public proof-of-concept exploit or evidence of in-the-wild exploitation has been observed as of the time of disclosure. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. Patchstack classifies this as high priority and notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No official patch from the vendor is available as of the publication date (Patchstack).
../../../../wp-config.php or /etc/passwd).../, ..%2F, %2e%2e%2f) in parameters; requests targeting sensitive file paths such as wp-config.php or /etc/passwd.wp-config.php; presence of newly uploaded files (e.g., images with embedded PHP code) in WordPress upload directories.As of the disclosure date (August 2, 2025), no official patch from ThemeMove is available for MinimogWP. Patchstack has issued a virtual patching/mitigation rule for Patchstack-protected sites to block exploitation attempts until an official fix is released. Site administrators should implement Web Application Firewall (WAF) rules to detect and block path traversal and file inclusion attempts, restrict file inclusion permissions at the server level, and conduct a security audit of the WordPress installation. Monitoring for an official patch from ThemeMove and applying it immediately upon release is strongly recommended (Patchstack).
The vulnerability was discovered and disclosed by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity and coordinated through Patchstack's vulnerability disclosure program. Patchstack has classified it as high priority, noting that LFI vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites. No significant broader media coverage or notable social media commentary has been identified beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."