CVE-2025-64205: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64205 is a PHP Local File Inclusion (LFI) vulnerability in the TieLabs Jannah WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement). It affects all versions of the Jannah theme up to and including 7.6.0, and was reported by researcher João Pedro S Alcântara (Kinorth) on September 29, 2025, with public disclosure on October 29, 2025. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) per NVD, and 8.1 (High) per Patchstack (Patchstack).

Technical details

The root cause is improper control of filenames used in PHP include/require statements within the Jannah theme (CWE-98), which allows an attacker to manipulate file path parameters to include arbitrary local files from the server. Because no authentication or user interaction is required and the attack is conducted over the network with low complexity, the vulnerability is trivially exploitable by unauthenticated remote attackers. The flaw is classified under OWASP Top 10 A1: Broken Access Control and maps to CAPEC-193 (PHP Remote File Inclusion). No public proof-of-concept exploit code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an unauthenticated attacker to read arbitrary local files on the web server, including sensitive configuration files such as WordPress wp-config.php (which contains database credentials), system files, and other data accessible to the web server process. The high confidentiality impact means critical data — including database credentials — could be exposed, potentially enabling complete database takeover depending on server configuration. Integrity impact is rated none and availability impact is low, making data exfiltration the primary risk (Patchstack).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack rates this as high priority and notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Jannah theme version 7.6.0 or earlier using tools like WPScan, Shodan, or Google dorks (e.g., inurl:wp-content/themes/jannah).
  2. Identify vulnerable parameter: Locate the theme's file inclusion endpoint or parameter that accepts a filename or path input without proper sanitization.
  3. Craft malicious request: Send an unauthenticated HTTP request with a manipulated file path parameter (e.g., path traversal sequences like ../../../../wp-config.php) targeting the vulnerable include/require logic in the theme.
  4. Retrieve sensitive files: The server processes the crafted filename and returns the contents of the requested local file (e.g., wp-config.php containing database credentials) in the HTTP response.
  5. Escalate access: Use exposed database credentials or other sensitive data to attempt database access, privilege escalation, or further lateral movement within the hosting environment (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP GET or POST requests to Jannah theme endpoints containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) or references to sensitive files (wp-config.php, /etc/passwd) in query parameters or request bodies.
  • Logs: Web server access logs (Apache/Nginx) showing requests with encoded path traversal patterns targeting theme-related PHP files; repeated 200 OK responses to requests with suspicious file path parameters.
  • File System: No direct file system artifacts expected from read-only LFI exploitation; however, if chained with other vulnerabilities, watch for new or modified PHP files in the theme directory (wp-content/themes/jannah/).
  • Application Logs: WordPress debug logs (wp-content/debug.log) showing PHP warnings or errors related to file inclusion with unexpected file paths.

Mitigation and workarounds

TieLabs has released Jannah version 7.6.1 as the patched release, and all users should upgrade immediately from any version at or below 7.6.0. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until the theme is updated. Additional hardening steps include implementing strict input validation for any file inclusion operations, using allowlists for permitted file paths, and applying the principle of least privilege to the web server process (Patchstack).

Community reactions

The vulnerability was discovered and disclosed through Patchstack's Vulnerability Disclosure Program (VDP) by researcher João Pedro S Alcântara (Kinorth). Patchstack has classified it as high priority and warned that LFI vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites. No significant broader media coverage or notable social media discussion beyond automated CVE tracking feeds has been identified (Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management