
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67934 is a Local File Inclusion (LFI) vulnerability in the Mikado-Themes Wellspring WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all Wellspring theme versions prior to 2.8 and allows unauthenticated remote attackers to include and execute arbitrary local files on the server. The vulnerability was reported on October 24, 2025, by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity, and publicly disclosed on January 6–8, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assigned by Patchstack (Patchstack).
The vulnerability stems from improper validation and sanitization of filename parameters used in PHP include/require statements within the Wellspring theme (CWE-98). An attacker can craft a malicious HTTP request that manipulates a file path parameter, causing the server to include arbitrary local files — a classic PHP Local File Inclusion (LFI) attack pattern (CAPEC-193). Exploitation requires no authentication and no user interaction, though it is rated as high complexity. No public proof-of-concept exploit code has been identified at this time (Patchstack).
Successful exploitation could allow an attacker to read sensitive local files on the server, such as WordPress configuration files (wp-config.php) containing database credentials, potentially enabling full database takeover. High confidentiality, integrity, and availability impacts are possible, as exposed credentials could facilitate lateral movement or complete site compromise. The vulnerability is unauthenticated, making it accessible to any remote attacker targeting WordPress sites running the affected theme (Patchstack).
No public proof-of-concept exploit or evidence of active in-the-wild exploitation has been reported as of the time of disclosure. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. No threat actor attribution is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority and notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites (Patchstack).
include/require statement.../../) targeting sensitive files such as /etc/passwd or wp-config.php.wp-config.php to access the WordPress database directly, enabling account takeover, data exfiltration, or further compromise (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters or POST body.wp-config.php, /etc/passwd, or /etc/shadow by the web server process.The primary remediation is to update the Wellspring theme to version 2.8 or later, which contains the fix for this vulnerability (Patchstack). As a temporary workaround, Patchstack has issued a virtual patching/mitigation rule for subscribers to block exploitation attempts until the theme is updated. Additional hardening measures include setting allow_url_include = Off in php.ini, implementing strict whitelist-based validation for any file path inputs, and restricting web server file system permissions to limit exposure.
Wordfence included CVE-2025-67934 in its weekly WordPress vulnerability report for January 5–11, 2026, highlighting it among notable disclosures for that period (Wordfence Blog). The vulnerability was also noted on security-focused social media accounts including TheHackerWire on Mastodon and Bluesky shortly after disclosure. No significant vendor statements or major media coverage beyond routine vulnerability reporting have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."