
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67914 is a Path Traversal vulnerability (CWE-35: .../...//) in the beeteam368 VidMov WordPress theme, affecting all versions up to and including 2.3.8. The vulnerability was reported by security researcher Denver Jackson on October 13, 2025, and published by Patchstack on January 2, 2026, with CVE assignment on January 8, 2026. It has a CVSS v3.1 base score of 7.7 (High) as assessed by Patchstack, requiring only Subscriber-level privileges (Patchstack).
The vulnerability is classified as CWE-35 (Path Traversal: .../...//), a variant of improper limitation of a pathname to a restricted directory (CWE-22). The .../...// obfuscation technique is used to bypass naive path sanitization filters that strip ../ sequences, allowing an attacker to traverse outside the intended directory. Exploitation requires at minimum Subscriber-level authentication on the WordPress site, and the attack is delivered over the network with low complexity. No detailed technical write-up or public PoC code has been identified at this time (Patchstack).
Successful exploitation allows an authenticated attacker (Subscriber or higher) to read or write arbitrary files outside the intended web root on the server hosting the WordPress site, with a high integrity impact and changed scope per the Patchstack CVSS assessment. This could expose sensitive server-side files such as WordPress configuration files (e.g., wp-config.php) containing database credentials, or allow unauthorized file writes that could lead to further compromise. The vulnerability is classified under OWASP Top 10 A1: Broken Access Control (Patchstack).
No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported for CVE-2025-67914. The EPSS score is approximately 0.021% (0.000210), indicating a low current probability of exploitation in the wild. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has issued a virtual patching/mitigation rule for its subscribers (Patchstack).
style.css files..../...// path traversal sequence (e.g., .../...//wp-config.php) to bypass sanitization filters.wp-config.php for database credentials) or write malicious files to achieve persistent access or further lateral movement (Patchstack)..../...// or URL-encoded variants (e.g., %2e%2e%2e%2f%2e%2e%2e%2f%2f) in path or query parameters.wp-config.php, .htaccess, or files outside the WordPress web root; presence of newly created web shells or backdoor scripts in the theme directory.The vulnerability is patched in VidMov version 2.3.9; administrators should update the theme immediately to this version or later (Patchstack). As an interim measure, Patchstack has issued a virtual patching rule for its subscribers that blocks exploitation attempts until the theme is updated. If updating is not immediately possible, consider restricting Subscriber-level user registration or disabling the VidMov theme until the patch can be applied.
The vulnerability was noted in automated threat intelligence feeds and aggregators including Vulners, VulDB, and radar.offseq.com shortly after publication. Patchstack, the disclosing CNA, characterized it as high priority and warned it is the type of vulnerability commonly leveraged in mass WordPress exploit campaigns. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."