CVE-2025-67925: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67925 is a Local File Inclusion (LFI) vulnerability in the zozothemes Corpkit WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Corpkit theme through version 2.0, and was reported by researcher "Bonds" on October 19, 2025, with public disclosure on January 5–8, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) as assessed by Patchstack, with the required privilege level noted as Subscriber (Patchstack, NVD).

Technical details

The root cause is improper sanitization and validation of user-controlled input passed to PHP include or require statements within the Corpkit WordPress theme (CWE-98). An attacker with at minimum Subscriber-level privileges can manipulate a filename parameter to cause the server to include arbitrary local files, potentially exposing sensitive server-side content. The attack vector is network-based with high attack complexity, requiring low privileges but no user interaction. No public proof-of-concept exploit code has been identified at this time (Patchstack, NVD).

Impact

Successful exploitation allows an attacker to include and read arbitrary local files on the web server, such as WordPress configuration files (e.g., wp-config.php) that contain database credentials, potentially enabling complete database takeover. High confidentiality and integrity impacts are expected, as sensitive credentials and application data may be exposed or manipulated. In worst-case scenarios, if the server is configured to execute included files, this could escalate to remote code execution (Patchstack).

Exploitability

There is no known public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack, NVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Corpkit theme version 2.0 or earlier via tools like WPScan, Shodan, or by inspecting theme metadata in publicly accessible style.css files.
  2. Obtain low-privilege access: Register or obtain a Subscriber-level account on the target WordPress site, as the vulnerability requires at minimum this privilege level.
  3. Identify vulnerable parameter: Locate the theme functionality that passes user-controlled input to a PHP include or require statement — typically a template or file-loading parameter in a theme page or shortcode.
  4. Craft LFI payload: Manipulate the vulnerable parameter with a path traversal sequence (e.g., ../../../../wp-config.php) to reference sensitive local files on the server.
  5. Exfiltrate sensitive data: Review the server response for included file contents, such as database credentials from wp-config.php, which can then be used for database access or further lateral movement (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests to WordPress theme endpoints containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.
  • Logs: WordPress or web server access logs showing repeated requests to theme-related URLs with encoded or plaintext directory traversal patterns; HTTP 200 responses to requests containing file path parameters pointing to system files.
  • File System: Unexpected access to sensitive files such as wp-config.php, /etc/passwd, or other system configuration files as reflected in server access logs.
  • Process: Unusual database connection attempts from external IPs following potential credential exposure via wp-config.php inclusion.

Mitigation and workarounds

The patched version of the Corpkit theme is 2.0.1 — administrators should update immediately from the WordPress theme repository or their hosting provider. Patchstack has also issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until the theme is updated. As additional hardening measures, restrict PHP file inclusion capabilities using open_basedir in php.ini to limit accessible directories, and implement input validation for all file inclusion operations. Sites unable to update immediately should consider temporarily deactivating the theme or consulting their hosting provider (Patchstack).

Community reactions

Wordfence included CVE-2025-67925 in their weekly WordPress vulnerability report covering January 5–11, 2026, highlighting it among notable theme vulnerabilities for that period (Wordfence Blog). The vulnerability was also noted by TheHackerWire on social platforms including Mastodon and Infosec.exchange shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond standard vulnerability reporting has been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management