
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64373 is a PHP Local File Inclusion (LFI) vulnerability in the Traveler WordPress theme by ShineTheme. It stems from improper control of filename parameters used in PHP include/require statements, allowing attackers to manipulate file paths and access sensitive server files. The vulnerability affects all Traveler theme versions prior to 3.2.6 and was published on December 18, 2025, with Patchstack credited as the assigner. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, EUVD).
The root cause is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is insufficiently validated before being passed to PHP file inclusion functions. An attacker can craft a malicious network request that manipulates the filename parameter to traverse the file system and include arbitrary local files. Exploitation requires user interaction (e.g., a victim visiting a crafted URL or triggering a specific action), but no authentication is required. No public proof-of-concept code has been identified at this time (Feedly).
Successful exploitation could allow an unauthenticated attacker to read sensitive system files such as /etc/passwd, WordPress configuration files (e.g., wp-config.php) containing database credentials, and other server-side files. This poses a high risk to both confidentiality and integrity of the affected WordPress site, potentially enabling credential theft, further lateral movement within the hosting environment, or escalation to remote code execution if combined with file upload capabilities. Availability is not directly impacted (Feedly).
There is currently no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. The attack vector is network-based but requires user interaction, which somewhat limits opportunistic exploitation (Feedly).
include/require statement.../../../../wp-config.php or ../../../../etc/passwd) as the filename parameter.../, %2e%2e%2f, ....//) in query parameters or POST body fields.wp-config.php, /etc/passwd, or other sensitive files in server access logs.The primary remediation is to upgrade the Traveler WordPress theme to version 3.2.6 or later, which addresses the improper file inclusion control. As interim mitigations, administrators should implement strict input validation and allowlisting for any file inclusion mechanisms, restrict file system permissions to limit what the web server process can read, and deploy Web Application Firewall (WAF) rules to detect and block path traversal patterns. Reviewing and auditing theme code for other unsanitized file inclusion calls is also recommended (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."