
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-60201 is a Local File Inclusion (LFI) vulnerability in the WP Customer Area WordPress plugin (slug: customer-area) by aguilatechnologies. It stems from improper control of filenames in PHP include/require statements (CWE-98), allowing unauthenticated remote attackers to include arbitrary local files. The vulnerability affects WP Customer Area versions up to and including 8.3.5, with no official patch available as of the latest reporting. It carries a CVSS v3.1 base score of 7.5 (High) and was published on November 6, 2025, with the Patchstack advisory updated July 21, 2025 (Patchstack).
The root cause is classified as CWE-98 — Improper Control of Filename for Include/Require Statement in PHP Program. The plugin fails to properly sanitize or validate user-supplied input before passing it to a PHP include() or require() statement, enabling an attacker to manipulate the file path to include arbitrary files from the server's local filesystem. No authentication is required, and exploitation can be initiated remotely over the network with low attack complexity and no user interaction. The vulnerability is categorized under OWASP Top 10 A3: Injection and maps to CAPEC-193 (PHP Remote File Inclusion) (Patchstack).
Successful exploitation allows an unauthenticated attacker to read arbitrary local files from the web server, including sensitive configuration files such as wp-config.php, which contains database credentials. This could lead to full database compromise, credential theft, and potentially complete site takeover depending on server configuration. Confidentiality impact is rated High, while integrity and availability are unaffected by this specific vector (Patchstack).
The vulnerability requires no authentication, no user interaction, and has low attack complexity, making it highly accessible to opportunistic attackers. Patchstack classifies it as high priority and notes it is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic or popularity. The EPSS score is approximately 0.056% (0.000560), indicating a currently low but non-negligible probability of exploitation in the near term. No specific threat actor attribution or confirmed in-the-wild exploitation has been reported, and it does not appear in the CISA KEV catalog at this time (Patchstack).
inurl:/wp-content/plugins/customer-area).include() or require() statement without proper sanitization.../../) targeting sensitive files such as wp-config.php or /etc/passwd.wp-config.php to access the WordPress database directly, enabling full site takeover or further lateral movement (Patchstack).../, ..%2F, %2e%2e%2f) in parameters; requests returning contents of system files.wp-config.php, /etc/passwd, or /etc/shadow.wp-config.php disclosure.As of the latest reporting, no official patch from the plugin developer is available for WP Customer Area versions ≤ 8.3.5. Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until an official fix is released. Site administrators are advised to deactivate and remove the plugin immediately if a patch is unavailable, restrict access to the WordPress admin panel, and monitor web server logs for traversal patterns. Hosting providers or web developers should be consulted if immediate removal is not feasible (Patchstack).
Patchstack, the assigning CNA, has flagged this vulnerability as high priority and warned it is the type likely to be used in mass-exploit campaigns against WordPress sites. The vulnerability was reported by researcher LVT-tholv2k on June 21, 2025, and published by Patchstack on July 21, 2025. No significant broader media coverage or notable social media commentary has been identified beyond the Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."