
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67925 is a Local File Inclusion (LFI) vulnerability in the zozothemes Corpkit WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Corpkit theme through version 2.0, and was reported by researcher "Bonds" on October 19, 2025, with public disclosure on January 5–8, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) as assessed by Patchstack, with the required privilege level noted as Subscriber (Patchstack, NVD).
The root cause is improper sanitization and validation of user-controlled input passed to PHP include or require statements within the Corpkit WordPress theme (CWE-98). An attacker with at minimum Subscriber-level privileges can manipulate a filename parameter to cause the server to include arbitrary local files, potentially exposing sensitive server-side content. The attack vector is network-based with high attack complexity, requiring low privileges but no user interaction. No public proof-of-concept exploit code has been identified at this time (Patchstack, NVD).
Successful exploitation allows an attacker to include and read arbitrary local files on the web server, such as WordPress configuration files (e.g., wp-config.php) that contain database credentials, potentially enabling complete database takeover. High confidentiality and integrity impacts are expected, as sensitive credentials and application data may be exposed or manipulated. In worst-case scenarios, if the server is configured to execute included files, this could escalate to remote code execution (Patchstack).
There is no known public proof-of-concept exploit and no confirmed evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. Patchstack classifies this as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack, NVD).
style.css files.include or require statement — typically a template or file-loading parameter in a theme page or shortcode.../../../../wp-config.php) to reference sensitive local files on the server.wp-config.php, which can then be used for database access or further lateral movement (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.wp-config.php, /etc/passwd, or other system configuration files as reflected in server access logs.wp-config.php inclusion.The patched version of the Corpkit theme is 2.0.1 — administrators should update immediately from the WordPress theme repository or their hosting provider. Patchstack has also issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until the theme is updated. As additional hardening measures, restrict PHP file inclusion capabilities using open_basedir in php.ini to limit accessible directories, and implement input validation for all file inclusion operations. Sites unable to update immediately should consider temporarily deactivating the theme or consulting their hosting provider (Patchstack).
Wordfence included CVE-2025-67925 in their weekly WordPress vulnerability report covering January 5–11, 2026, highlighting it among notable theme vulnerabilities for that period (Wordfence Blog). The vulnerability was also noted by TheHackerWire on social platforms including Mastodon and Infosec.exchange shortly after disclosure. No significant broader media coverage or notable researcher commentary beyond standard vulnerability reporting has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."