
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67937 is a PHP Local File Inclusion (LFI) vulnerability in the Mikado-Themes Hendon WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all Hendon theme versions prior to 1.7 and was reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity on October 24, 2025, with public disclosure on January 6–8, 2026. The vulnerability carries a CVSS v3.1 base score of 8.1 (High), as assessed by CISA-ADP (Patchstack, NVD).
The vulnerability stems from improper validation and sanitization of filenames passed to PHP include/require statements within the Hendon WordPress theme (CWE-98). An unauthenticated remote attacker can manipulate file path parameters to cause the server to include arbitrary local files, potentially exposing their contents. The attack vector is network-based with high attack complexity and requires no privileges or user interaction per the CISA-ADP CVSS assessment. No public proof-of-concept exploit code has been identified at this time (Patchstack, NVD).
Successful exploitation allows an attacker to include and read arbitrary local files on the web server, potentially exposing sensitive data such as WordPress configuration files (wp-config.php) containing database credentials, which could lead to complete database compromise. Confidentiality, integrity, and availability are all rated as high impact under the CISA-ADP scoring. In a worst-case scenario, access to credential files could enable lateral movement to the database layer or further server compromise (Patchstack).
There is no public proof-of-concept exploit and no confirmed in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack, NVD).
style.css files.include/require statement — typically exposed via HTTP GET or POST requests to theme-specific endpoints.../../wp-config.php or /etc/passwd) targeting the vulnerable include mechanism.wp-config.php, which can be used for further compromise (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.wp-config.php, /etc/passwd) in server audit logs if file auditing is enabled.The primary remediation is to update the Hendon WordPress theme to version 1.7 or later, which contains the fix for this vulnerability (Patchstack). As an interim measure, Patchstack has issued a virtual patching/mitigation rule for subscribers that blocks exploitation attempts until the theme is updated. Additional hardening steps include implementing input validation and whitelisting for any file inclusion mechanisms, deploying a Web Application Firewall (WAF) with rules to detect path traversal patterns, and auditing server logs for suspicious file inclusion activity.
Wordfence included this vulnerability in their weekly WordPress vulnerability report for January 5–11, 2026, highlighting it as part of a broader set of WordPress theme and plugin issues disclosed that week (Wordfence Blog). The vulnerability was also noted on social platforms including Bluesky and Mastodon by security news aggregators shortly after disclosure. No significant vendor statements beyond the Patchstack advisory have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."