CVE-2025-67914
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67914 is a Path Traversal vulnerability (CWE-35: .../...//) in the beeteam368 VidMov WordPress theme, affecting all versions up to and including 2.3.8. The vulnerability was reported by security researcher Denver Jackson on October 13, 2025, and published by Patchstack on January 2, 2026, with CVE assignment on January 8, 2026. It has a CVSS v3.1 base score of 7.7 (High) as assessed by Patchstack, requiring only Subscriber-level privileges (Patchstack).

Technical details

The vulnerability is classified as CWE-35 (Path Traversal: .../...//), a variant of improper limitation of a pathname to a restricted directory (CWE-22). The .../...// obfuscation technique is used to bypass naive path sanitization filters that strip ../ sequences, allowing an attacker to traverse outside the intended directory. Exploitation requires at minimum Subscriber-level authentication on the WordPress site, and the attack is delivered over the network with low complexity. No detailed technical write-up or public PoC code has been identified at this time (Patchstack).

Impact

Successful exploitation allows an authenticated attacker (Subscriber or higher) to read or write arbitrary files outside the intended web root on the server hosting the WordPress site, with a high integrity impact and changed scope per the Patchstack CVSS assessment. This could expose sensitive server-side files such as WordPress configuration files (e.g., wp-config.php) containing database credentials, or allow unauthorized file writes that could lead to further compromise. The vulnerability is classified under OWASP Top 10 A1: Broken Access Control (Patchstack).

Exploitability

No public proof-of-concept exploit code or confirmed in-the-wild exploitation has been reported for CVE-2025-67914. The EPSS score is approximately 0.021% (0.000210), indicating a low current probability of exploitation in the wild. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity. The CVE is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has issued a virtual patching/mitigation rule for its subscribers (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the VidMov theme version 2.3.8 or earlier, using tools such as WPScan or by inspecting theme metadata in publicly accessible style.css files.
  2. Authentication: Register or obtain a Subscriber-level account on the target WordPress site, as the vulnerability requires at minimum this privilege level.
  3. Craft malicious request: Construct an HTTP request targeting a vulnerable endpoint in the VidMov theme that accepts a file path parameter, embedding a .../...// path traversal sequence (e.g., .../...//wp-config.php) to bypass sanitization filters.
  4. Traverse directory: Submit the crafted request; the server processes the obfuscated traversal sequence and accesses files outside the intended directory.
  5. Achieve objective: Read sensitive files (e.g., wp-config.php for database credentials) or write malicious files to achieve persistent access or further lateral movement (Patchstack).

Indicators of compromise

  • Network: HTTP requests to WordPress endpoints associated with the VidMov theme containing .../...// or URL-encoded variants (e.g., %2e%2e%2e%2f%2e%2e%2e%2f%2f) in path or query parameters.
  • Logs: Web server access logs showing unusual file path patterns with repeated dot-slash sequences targeting theme-related endpoints; requests from low-privilege user accounts accessing sensitive file paths.
  • File System: Unexpected access or modification timestamps on sensitive files such as wp-config.php, .htaccess, or files outside the WordPress web root; presence of newly created web shells or backdoor scripts in the theme directory.
  • Process: Unusual PHP process activity reading files outside the WordPress installation directory.

Mitigation and workarounds

The vulnerability is patched in VidMov version 2.3.9; administrators should update the theme immediately to this version or later (Patchstack). As an interim measure, Patchstack has issued a virtual patching rule for its subscribers that blocks exploitation attempts until the theme is updated. If updating is not immediately possible, consider restricting Subscriber-level user registration or disabling the VidMov theme until the patch can be applied.

Community reactions

The vulnerability was noted in automated threat intelligence feeds and aggregators including Vulners, VulDB, and radar.offseq.com shortly after publication. Patchstack, the disclosing CNA, characterized it as high priority and warned it is the type of vulnerability commonly leveraged in mass WordPress exploit campaigns. No significant independent researcher commentary or major media coverage has been identified beyond standard vulnerability database entries.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-84293HIGH7.2
  • repeater-for-gravity-forms
NoYesSep 09, 2026
CVE-2026-83532MEDIUM6.8
  • custom-menu-wizard
NoNoSep 09, 2026
CVE-2026-19945MEDIUM6.4
  • wp-crowdfunding
NoYesSep 09, 2026
CVE-2026-7804MEDIUM6.1
  • woo-product-filter
NoYesSep 09, 2026
CVE-2026-11821MEDIUM5.4
  • wp-event-solution
NoYesSep 09, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management