CVE-2025-60070
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-60070 is a Code Injection (Arbitrary Code Execution) vulnerability in the Molla WordPress theme developed by The4. It affects all versions of the Molla theme up to and including version 1.5.13, and can be exploited by unauthenticated remote attackers. The vulnerability was reported on July 3, 2025, by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, and publicly disclosed on August 2, 2025. It carries a CVSS v3.1 base score of 6.5 (Medium), though Patchstack classifies it as High priority due to its unauthenticated nature and mass-exploit potential (Patchstack).

Technical details

The vulnerability is classified as CWE-94 (Improper Control of Generation of Code / Code Injection), falling under OWASP Top 10 category A3: Injection. The flaw allows attackers to inject and execute arbitrary code remotely without any authentication or user interaction, indicating that user-controlled input is passed unsanitized into a code execution context within the theme. Attack patterns associated with this vulnerability include CAPEC-242 (Code Injection), CAPEC-35 (Leverage Executable Code in Non-Executable Files), and CAPEC-77 (Manipulating User-Controlled Variables). No detailed technical write-up or public proof-of-concept code has been published as of the disclosure date (Patchstack).

Impact

Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code on the WordPress server hosting the Molla theme, resulting in low confidentiality and low integrity impact per the CVSS scoring. In practice, arbitrary code execution on a web server can lead to full site compromise, installation of web shells, data theft, defacement, or use of the server as a pivot point for further attacks against the hosting environment. All WordPress sites running Molla theme version 1.5.13 or earlier are at risk, regardless of site traffic or popularity, making them targets for mass-exploit campaigns (Patchstack).

Exploitability

No authentication or user interaction is required to exploit this vulnerability, significantly lowering the barrier for attackers. Patchstack explicitly warns that vulnerabilities of this type are used in mass-exploit campaigns targeting thousands of websites simultaneously. The EPSS score is approximately 0.029% (0.000290), indicating a currently low but non-negligible probability of exploitation in the near term. No specific threat actor attribution, active in-the-wild exploitation evidence, or inclusion in the CISA KEV catalog has been reported as of the disclosure date. No official patch is available from the vendor (Patchstack).

Mitigation and workarounds

As of the disclosure date (August 2, 2025), no official patch has been released by The4 for the Molla theme. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is available. Site owners are advised to either subscribe to Patchstack for automated mitigation, contact their hosting provider or web developer for assistance, or consider temporarily deactivating the Molla theme if no mitigation is in place. Monitoring for an official update from The4 and applying it promptly upon release is strongly recommended (Patchstack).

Community reactions

Patchstack, which coordinated the disclosure, classifies this vulnerability as high priority and warns of its potential for use in mass-exploit campaigns targeting WordPress sites. The vulnerability was discovered and reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, reflecting ongoing security research into WordPress theme security. No broader media coverage or notable social media commentary has been identified beyond the Patchstack advisory (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management