CVE-2025-67937: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67937 is a PHP Local File Inclusion (LFI) vulnerability in the Mikado-Themes Hendon WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all Hendon theme versions prior to 1.7 and was reported by Tran Nguyen Bao Khanh of VCI - VNPT Cyber Immunity on October 24, 2025, with public disclosure on January 6–8, 2026. The vulnerability carries a CVSS v3.1 base score of 8.1 (High), as assessed by CISA-ADP (Patchstack, NVD).

Technical details

The vulnerability stems from improper validation and sanitization of filenames passed to PHP include/require statements within the Hendon WordPress theme (CWE-98). An unauthenticated remote attacker can manipulate file path parameters to cause the server to include arbitrary local files, potentially exposing their contents. The attack vector is network-based with high attack complexity and requires no privileges or user interaction per the CISA-ADP CVSS assessment. No public proof-of-concept exploit code has been identified at this time (Patchstack, NVD).

Impact

Successful exploitation allows an attacker to include and read arbitrary local files on the web server, potentially exposing sensitive data such as WordPress configuration files (wp-config.php) containing database credentials, which could lead to complete database compromise. Confidentiality, integrity, and availability are all rated as high impact under the CISA-ADP scoring. In a worst-case scenario, access to credential files could enable lateral movement to the database layer or further server compromise (Patchstack).

Exploitability

There is no public proof-of-concept exploit and no confirmed in-the-wild exploitation as of the time of disclosure. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack notes that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale, regardless of site popularity (Patchstack, NVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Hendon theme (versions < 1.7) via passive scanning tools (e.g., WPScan, Shodan) or by inspecting theme metadata in publicly accessible style.css files.
  2. Identify vulnerable parameter: Locate theme functionality that accepts a filename or path parameter passed to a PHP include/require statement — typically exposed via HTTP GET or POST requests to theme-specific endpoints.
  3. Craft LFI payload: Construct a request with a manipulated file path parameter (e.g., ../../wp-config.php or /etc/passwd) targeting the vulnerable include mechanism.
  4. Send malicious request: Submit the crafted HTTP request to the target WordPress site without authentication.
  5. Extract sensitive data: Review the server response for included file contents, such as database credentials from wp-config.php, which can be used for further compromise (Patchstack).

Indicators of compromise

  • Network: Unusual HTTP requests to WordPress theme endpoints containing path traversal sequences (e.g., ../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.
  • Logs: Web server access logs showing requests with encoded or plaintext directory traversal patterns targeting theme PHP files; repeated 200 responses to atypical theme endpoints from a single IP.
  • File System: No direct file system artifacts expected from read-only LFI, but monitor for unexpected file reads of sensitive files (e.g., wp-config.php, /etc/passwd) in server audit logs if file auditing is enabled.
  • Application: WordPress error logs showing PHP include/require failures with unusual file paths, potentially indicating probing activity.

Mitigation and workarounds

The primary remediation is to update the Hendon WordPress theme to version 1.7 or later, which contains the fix for this vulnerability (Patchstack). As an interim measure, Patchstack has issued a virtual patching/mitigation rule for subscribers that blocks exploitation attempts until the theme is updated. Additional hardening steps include implementing input validation and whitelisting for any file inclusion mechanisms, deploying a Web Application Firewall (WAF) with rules to detect path traversal patterns, and auditing server logs for suspicious file inclusion activity.

Community reactions

Wordfence included this vulnerability in their weekly WordPress vulnerability report for January 5–11, 2026, highlighting it as part of a broader set of WordPress theme and plugin issues disclosed that week (Wordfence Blog). The vulnerability was also noted on social platforms including Bluesky and Mastodon by security news aggregators shortly after disclosure. No significant vendor statements beyond the Patchstack advisory have been identified.

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management