CVE-2025-67567
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67567 is a Sensitive Data Exposure vulnerability in the Sober WordPress theme developed by uixthemes. Classified under CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere), it allows unauthenticated remote attackers to retrieve embedded sensitive data from affected installations. All versions of the Sober theme up to and including 3.5.11 are affected. The vulnerability was published on December 9, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 5.3 (Medium) (Feedly, Patchstack).

Technical details

The root cause is classified as CWE-497 — Exposure of Sensitive System Information to an Unauthorized Control Sphere — meaning the Sober theme inadvertently exposes sensitive system or configuration data in a manner accessible to unauthorized parties. The attack vector is network-based, requires no authentication, no user interaction, and low attack complexity, making it trivially exploitable by any remote attacker. The associated CAPEC pattern is CAPEC-170 (Web Application Fingerprinting), suggesting the exposed data may include information useful for further reconnaissance or targeted attacks against the WordPress installation (Feedly).

Impact

Successful exploitation results in a low-level confidentiality impact, with no effect on integrity or availability. An unauthenticated attacker can retrieve embedded sensitive data — such as system configuration details, API keys, or internal path information — from WordPress sites running the vulnerable Sober theme. While the direct impact is limited, the exposed information could facilitate further attacks, including targeted exploitation of other vulnerabilities or credential-based attacks against the WordPress environment (Feedly).

Exploitability

No public proof-of-concept exploit code or in-the-wild exploitation has been reported for CVE-2025-67567 as of the available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.039%, indicating a very low probability of exploitation in the near term. The low attack complexity and lack of authentication requirements do, however, lower the barrier for opportunistic exploitation (Feedly).

Mitigation and workarounds

Users of the Sober WordPress theme should update to a version beyond 3.5.11 if a patched release is available from uixthemes. If no patch is yet available, site administrators should consider deactivating the theme until a fix is released, or restricting access to sensitive endpoints via web server configuration (e.g., blocking direct access to theme files through .htaccess rules). Regularly auditing WordPress theme and plugin versions using security tools such as Patchstack or WPScan is recommended as a general best practice (Patchstack).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-13784CRITICAL9.8
  • arforms-form-builder
NoYesAug 16, 2026
CVE-2026-17087HIGH7.5
  • wp-travel-engine
NoYesAug 16, 2026
CVE-2026-2497HIGH7.2
  • gallery-plugin
NoYesAug 16, 2026
CVE-2026-17608MEDIUM6.5
  • wp-compress-image-optimizer
NoYesAug 16, 2026
CVE-2026-2357MEDIUM6.4
  • bold-page-builder
NoYesAug 16, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management