CVE-2025-63062: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-63062 is a Local File Inclusion (LFI) vulnerability in the AndonDesign UDesign Core WordPress plugin, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects UDesign Core versions up to and including 4.14.0, with no official patch available at the time of disclosure. The vulnerability was reported by João Pedro S Alcântara (Kinorth) on September 15, 2025, and published by Patchstack on October 15, 2025; it was assigned a CVE ID on December 9, 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).

Technical details

The root cause is improper validation of filenames used in PHP include/require statements (CWE-98), which allows an attacker to manipulate file path parameters to include arbitrary local files from the server's filesystem. Exploitation requires at least Contributor- or Developer-level privileges on the WordPress site, meaning the attacker must have an authenticated session. The attack is delivered over the network with high attack complexity, and no user interaction is required beyond the attacker's own authenticated request. No public proof-of-concept code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an attacker to read arbitrary local files on the web server, including sensitive configuration files such as wp-config.php, which contains database credentials. This can lead to complete database takeover, exposure of secret keys, and potential escalation to remote code execution if writable directories or log files can be leveraged for log poisoning. Confidentiality, integrity, and availability are all rated as High impact (Patchstack).

Exploitability

No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-63062. The EPSS score is approximately 0.05%, indicating a low probability of exploitation in the near term. Patchstack rates the priority as "Low," noting the issue is unlikely to be exploited despite the CVSS score of 7.5. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the Contributor or Developer privilege level, which limits the attacker pool (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the UDesign Core plugin (version ≤ 4.14.0) using tools like WPScan or Shodan, or by checking the plugin's readme.txt file for version disclosure.
  2. Obtain authenticated access: Acquire Contributor- or Developer-level credentials through phishing, credential stuffing, or by registering as a contributor if open registration is enabled.
  3. Identify vulnerable parameter: Locate the plugin functionality that accepts a filename or path parameter used in a PHP include/require statement within the UDesign Core plugin code.
  4. Craft LFI payload: Submit a crafted request with a manipulated file path parameter (e.g., ../../../../wp-config.php or similar directory traversal sequences) targeting the vulnerable endpoint.
  5. Exfiltrate sensitive data: Review the server response for the contents of included files, extracting database credentials, secret keys, or other sensitive configuration data from files such as wp-config.php (Patchstack).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated requests with directory traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters or POST body fields associated with UDesign Core plugin endpoints.
  • Logs: PHP error logs referencing unexpected file inclusion paths or include/require failures for files outside the plugin directory.
  • Network: Unusual outbound connections from the web server following authenticated plugin interactions, potentially indicating secondary payload delivery.
  • File System: Unexpected access timestamps on sensitive files such as wp-config.php, server configuration files, or /etc/passwd correlating with plugin request times.

Mitigation and workarounds

As of the disclosure date, no official patch has been released by AndonDesign for UDesign Core. Site administrators should consider deactivating and removing the UDesign Core plugin until a patched version is available. Access to the WordPress backend should be restricted to trusted users, and Contributor/Developer role assignments should be audited and minimized. Web application firewalls (WAFs) with LFI detection rules, such as those provided by Patchstack's virtual patching, can serve as a compensating control (Patchstack).

Community reactions

Patchstack, which discovered and disclosed the vulnerability through researcher João Pedro S Alcântara (Kinorth), rates the issue as low priority and notes it is unlikely to be exploited in practice despite the elevated CVSS score. No significant vendor statements, broader media coverage, or notable community discussion has been identified beyond the initial Patchstack advisory (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management