
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64205 is a PHP Local File Inclusion (LFI) vulnerability in the TieLabs Jannah WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement). It affects all versions of the Jannah theme up to and including 7.6.0, and was reported by researcher João Pedro S Alcântara (Kinorth) on September 29, 2025, with public disclosure on October 29, 2025. The vulnerability carries a CVSS v3.1 base score of 8.2 (High) per NVD, and 8.1 (High) per Patchstack (Patchstack).
The root cause is improper control of filenames used in PHP include/require statements within the Jannah theme (CWE-98), which allows an attacker to manipulate file path parameters to include arbitrary local files from the server. Because no authentication or user interaction is required and the attack is conducted over the network with low complexity, the vulnerability is trivially exploitable by unauthenticated remote attackers. The flaw is classified under OWASP Top 10 A1: Broken Access Control and maps to CAPEC-193 (PHP Remote File Inclusion). No public proof-of-concept exploit code has been identified at this time (Patchstack).
Successful exploitation allows an unauthenticated attacker to read arbitrary local files on the web server, including sensitive configuration files such as WordPress wp-config.php (which contains database credentials), system files, and other data accessible to the web server process. The high confidentiality impact means critical data — including database credentials — could be exposed, potentially enabling complete database takeover depending on server configuration. Integrity impact is rated none and availability impact is low, making data exfiltration the primary risk (Patchstack).
No public proof-of-concept exploit code has been identified, and there is no evidence of active in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack rates this as high priority and notes that vulnerabilities of this class are frequently used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
inurl:wp-content/themes/jannah).../../../../wp-config.php) targeting the vulnerable include/require logic in the theme.wp-config.php containing database credentials) in the HTTP response.../, ..%2F, %2e%2e%2f) or references to sensitive files (wp-config.php, /etc/passwd) in query parameters or request bodies.wp-content/themes/jannah/).wp-content/debug.log) showing PHP warnings or errors related to file inclusion with unexpected file paths.TieLabs has released Jannah version 7.6.1 as the patched release, and all users should upgrade immediately from any version at or below 7.6.0. As an interim measure, Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until the theme is updated. Additional hardening steps include implementing strict input validation for any file inclusion operations, using allowlists for permitted file paths, and applying the principle of least privilege to the web server process (Patchstack).
The vulnerability was discovered and disclosed through Patchstack's Vulnerability Disclosure Program (VDP) by researcher João Pedro S Alcântara (Kinorth). Patchstack has classified it as high priority and warned that LFI vulnerabilities of this type are commonly leveraged in mass-exploit campaigns against WordPress sites. No significant broader media coverage or notable social media discussion beyond automated CVE tracking feeds has been identified (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."