
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67567 is a Sensitive Data Exposure vulnerability in the Sober WordPress theme developed by uixthemes. Classified under CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), it allows unauthenticated remote attackers to retrieve embedded sensitive data from affected installations. All versions of the Sober theme up to and including 3.5.11 are affected. The vulnerability was published on December 9, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).
The root cause is classified as CWE-497 — Exposure of Sensitive System Information to an Unauthorized Control Sphere — meaning the Sober theme inadvertently exposes sensitive system or configuration data in a manner accessible to unauthorized parties. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The associated CAPEC pattern is CAPEC-170 (Web Application Fingerprinting), suggesting the exposed data may include information useful for further reconnaissance or targeted attacks against the WordPress installation (Feedly).
Successful exploitation results in a low-level confidentiality impact, with no effect on integrity or availability. An unauthenticated attacker can retrieve embedded sensitive data — such as system configuration details, API keys, or internal path information — from WordPress sites running the vulnerable Sober theme. While the direct impact is limited, the exposed information could facilitate further attacks, including targeted exploitation of other vulnerabilities or credential-based attacks against the WordPress environment (Feedly).
No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-67567 as of the available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039%, indicating a very low probability of exploitation in the near term. The low attack complexity and lack of authentication requirements do, however, lower the barrier for opportunistic exploitation (Feedly).
Users of the Sober WordPress theme should update to a version beyond 3.5.11 if a patched release is available from uixthemes. If no patch is yet available, site administrators should consider deactivating the theme until a fix is released, or restricting access to sensitive endpoints via web server configuration (e.g., blocking direct access to theme files through .htaccess rules). Regularly auditing WordPress theme and plugin versions using security tools such as Patchstack or WPScan is recommended as a general best practice (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."