
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-63062 is a Local File Inclusion (LFI) vulnerability in the AndonDesign UDesign Core WordPress plugin, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects UDesign Core versions up to and including 4.14.0, with no official patch available at the time of disclosure. The vulnerability was reported by João Pedro S Alcântara (Kinorth) on September 15, 2025, and published by Patchstack on October 15, 2025; it was assigned a CVE ID on December 9, 2025. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack).
The root cause is improper validation of filenames used in PHP include/require statements (CWE-98), which allows an attacker to manipulate file path parameters to include arbitrary local files from the server's filesystem. Exploitation requires at least Contributor- or Developer-level privileges on the WordPress site, meaning the attacker must have an authenticated session. The attack is delivered over the network with high attack complexity, and no user interaction is required beyond the attacker's own authenticated request. No public proof-of-concept code has been identified at this time (Patchstack).
Successful exploitation allows an attacker to read arbitrary local files on the web server, including sensitive configuration files such as wp-config.php, which contains database credentials. This can lead to complete database takeover, exposure of secret keys, and potential escalation to remote code execution if writable directories or log files can be leveraged for log poisoning. Confidentiality, integrity, and availability are all rated as High impact (Patchstack).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-63062. The EPSS score is approximately 0.05%, indicating a low probability of exploitation in the near term. Patchstack rates the priority as "Low," noting the issue is unlikely to be exploited despite the CVSS score of 7.5. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access at the Contributor or Developer privilege level, which limits the attacker pool (Patchstack).
include/require statement within the UDesign Core plugin code.../../../../wp-config.php or similar directory traversal sequences) targeting the vulnerable endpoint.wp-config.php (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters or POST body fields associated with UDesign Core plugin endpoints.include/require failures for files outside the plugin directory.wp-config.php, server configuration files, or /etc/passwd correlating with plugin request times.As of the disclosure date, no official patch has been released by AndonDesign for UDesign Core. Site administrators should consider deactivating and removing the UDesign Core plugin until a patched version is available. Access to the WordPress backend should be restricted to trusted users, and Contributor/Developer role assignments should be audited and minimized. Web application firewalls (WAFs) with LFI detection rules, such as those provided by Patchstack's virtual patching, can serve as a compensating control (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through researcher João Pedro S Alcântara (Kinorth), rates the issue as low priority and notes it is unlikely to be exploited in practice despite the elevated CVSS score. No significant vendor statements, broader media coverage, or notable community discussion has been identified beyond the initial Patchstack advisory (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."