CVE-2025-64373: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-64373 is a PHP Local File Inclusion (LFI) vulnerability in the Traveler WordPress theme by ShineTheme. It stems from improper control of filename parameters used in PHP include/require statements, allowing attackers to manipulate file paths and access sensitive server files. The vulnerability affects all Traveler theme versions prior to 3.2.6 and was published on December 18, 2025, with Patchstack credited as the assigner. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, EUVD).

Technical details

The root cause is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is insufficiently validated before being passed to PHP file inclusion functions. An attacker can craft a malicious network request that manipulates the filename parameter to traverse the file system and include arbitrary local files. Exploitation requires user interaction (e.g., a victim visiting a crafted URL or triggering a specific action), but no authentication is required. No public proof-of-concept code has been identified at this time (Feedly).

Impact

Successful exploitation could allow an unauthenticated attacker to read sensitive system files such as /etc/passwd, WordPress configuration files (e.g., wp-config.php) containing database credentials, and other server-side files. This poses a high risk to both confidentiality and integrity of the affected WordPress site, potentially enabling credential theft, further lateral movement within the hosting environment, or escalation to remote code execution if combined with file upload capabilities. Availability is not directly impacted (Feedly).

Exploitability

There is currently no public proof-of-concept exploit and no evidence of active in-the-wild exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. The attack vector is network-based but requires user interaction, which somewhat limits opportunistic exploitation (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Traveler theme (versions < 3.2.6) via passive scanning tools (e.g., WPScan, Shodan) or by inspecting theme metadata in page source.
  2. Identify vulnerable parameter: Locate the theme's file inclusion mechanism — a parameter or endpoint that accepts a filename or path value passed to a PHP include/require statement.
  3. Craft malicious request: Construct a URL or HTTP request that supplies a path-traversal payload (e.g., ../../../../wp-config.php or ../../../../etc/passwd) as the filename parameter.
  4. Trigger user interaction: Deliver the crafted URL to a victim (e.g., via phishing or a malicious link) to trigger the vulnerable code path, since user interaction is required.
  5. Exfiltrate sensitive data: Review the server response for the contents of the included file, extracting credentials or configuration data for further exploitation (Feedly).

Indicators of compromise

  • Network: Unusual HTTP requests to WordPress theme endpoints containing path traversal sequences (e.g., ../, %2e%2e%2f, ....//) in query parameters or POST body fields.
  • Logs: WordPress or web server access logs showing requests with encoded traversal strings targeting theme-specific PHP files; HTTP 200 responses to requests containing file path parameters pointing outside the web root.
  • File System: No direct file system artifacts expected from read-only LFI, but monitor for unexpected access to wp-config.php, /etc/passwd, or other sensitive files in server access logs.
  • Process: Unexpected PHP process activity reading files outside the WordPress installation directory, detectable via auditd or similar host-based monitoring (Feedly).

Mitigation and workarounds

The primary remediation is to upgrade the Traveler WordPress theme to version 3.2.6 or later, which addresses the improper file inclusion control. As interim mitigations, administrators should implement strict input validation and allowlisting for any file inclusion mechanisms, restrict file system permissions to limit what the web server process can read, and deploy Web Application Firewall (WAF) rules to detect and block path traversal patterns. Reviewing and auditing theme code for other unsanitized file inclusion calls is also recommended (Feedly).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management