CVE-2025-60069: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60069 is a PHP Local File Inclusion (LFI) vulnerability in the ThemeMove MinimogWP WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement). It affects all MinimogWP versions up to and including 3.9.6, and was reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity on July 3, 2025, with public disclosure by Patchstack on August 2, 2025. The vulnerability carries a CVSS v3.1 base score of 8.1 (High), exploitable remotely without authentication (Patchstack).

Technical details

The root cause is improper control of filename parameters used in PHP include/require statements within the MinimogWP theme (CWE-98), which allows an attacker to manipulate file path inputs to include arbitrary local files. The attack vector is network-based, requires no authentication or user interaction, but has high attack complexity, suggesting some precondition or constraint must be met (e.g., specific server configuration or parameter guessing). Exploitation falls under OWASP Top 10 A3: Injection and CAPEC-193 (PHP Remote File Inclusion). No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an attacker to include and expose the contents of arbitrary local files on the web server, with high impacts to confidentiality, integrity, and availability. Sensitive files such as WordPress wp-config.php (containing database credentials) could be read, potentially enabling complete database takeover. Depending on server configuration, inclusion of attacker-controlled files (e.g., uploaded content) could escalate to remote code execution, fully compromising the affected WordPress site (Patchstack).

Exploitability

No public proof-of-concept exploit or evidence of in-the-wild exploitation has been observed as of the time of disclosure. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. Patchstack classifies this as high priority and notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No official patch from the vendor is available as of the publication date (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the MinimogWP theme (version ≤ 3.9.6) via passive fingerprinting tools (e.g., WPScan, Shodan, or HTTP response headers/theme file paths).
  2. Identify vulnerable parameter: Locate the theme's PHP file inclusion point by reviewing publicly available theme source code or probing known endpoints that accept file path parameters.
  3. Craft malicious request: Send a crafted HTTP request to the vulnerable endpoint with a manipulated filename parameter pointing to a sensitive local file (e.g., ../../../../wp-config.php or /etc/passwd).
  4. Extract sensitive data: Review the server's HTTP response for the included file's contents, which may expose database credentials, API keys, or other configuration secrets.
  5. Escalate if possible: If the server allows inclusion of uploaded files (e.g., images with embedded PHP), attempt to include a previously uploaded malicious file to achieve remote code execution (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP GET or POST requests to MinimogWP theme endpoints containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in parameters; requests targeting sensitive file paths such as wp-config.php or /etc/passwd.
  • Logs: Web server access logs showing repeated requests with encoded or obfuscated path traversal strings to theme-related PHP endpoints; HTTP 200 responses to requests containing file path parameters that should not return file contents.
  • File System: Unexpected access timestamps on sensitive files such as wp-config.php; presence of newly uploaded files (e.g., images with embedded PHP code) in WordPress upload directories.
  • Process: Unusual PHP process activity spawning child processes or making outbound network connections following theme file inclusion requests.

Mitigation and workarounds

As of the disclosure date (August 2, 2025), no official patch from ThemeMove is available for MinimogWP. Patchstack has issued a virtual patching/mitigation rule for Patchstack-protected sites to block exploitation attempts until an official fix is released. Site administrators should implement Web Application Firewall (WAF) rules to detect and block path traversal and file inclusion attempts, restrict file inclusion permissions at the server level, and conduct a security audit of the WordPress installation. Monitoring for an official patch from ThemeMove and applying it immediately upon release is strongly recommended (Patchstack).

Community reactions

The vulnerability was discovered and disclosed by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity and coordinated through Patchstack's vulnerability disclosure program. Patchstack has classified it as high priority, noting that LFI vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites. No significant broader media coverage or notable social media commentary has been identified beyond the Patchstack advisory (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management