
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67938 is a Local File Inclusion (LFI) vulnerability in the Mikado-Themes Biagiotti WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all Biagiotti theme versions prior to 3.5.2 and was reported by researcher Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on October 24, 2025, with public disclosure on January 15–22, 2026. The vulnerability carries a CVSS v3.1 base score of 8.1 (High), as assessed by CISA-ADP (Patchstack, NVD).
The vulnerability stems from improper validation and sanitization of user-supplied input used in PHP include/require statements within the Biagiotti WordPress theme (CWE-98). An unauthenticated remote attacker can manipulate filename parameters passed to these statements to include arbitrary local files on the server, potentially exposing sensitive content or executing malicious PHP code already present on the filesystem. Exploitation requires high attack complexity (e.g., specific preconditions such as file upload capability or knowledge of file paths), but no authentication or user interaction is needed (Patchstack, NVD).
Successful exploitation allows an attacker to read arbitrary local files on the web server, potentially exposing sensitive data such as database credentials, WordPress configuration files (e.g., wp-config.php), and other server-side files. If combined with a file upload vector, an attacker could include and execute malicious PHP code, leading to full server compromise. The vulnerability has high confidentiality, integrity, and availability impacts, and could enable complete database takeover depending on server configuration (Patchstack).
There is no public proof-of-concept exploit code and no evidence of in-the-wild exploitation at this time (Patchstack). The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Patchstack has classified it as high priority, noting that vulnerabilities of this class are commonly used in mass-exploit campaigns targeting WordPress sites at scale.
../../../../wp-config.php) to trigger the LFI.wp-config.php.../, ..%2F, %2e%2e%2f) in filename or template parameters./wp-content/uploads/) that could be used as LFI payloads; access timestamps on sensitive files like wp-config.php updated unexpectedly.The primary remediation is to update the Biagiotti WordPress theme to version 3.5.2 or later, which contains the fix for this vulnerability (Patchstack). For sites unable to update immediately, Patchstack has issued a virtual patching/mitigation rule to block exploitation attempts. Additional interim measures include implementing Web Application Firewall (WAF) rules to detect and block path traversal patterns, restricting file system permissions to limit readable files, and disabling unnecessary file upload functionality to reduce LFI escalation risk.
Wordfence included this vulnerability in their weekly WordPress vulnerability report for the period of January 12–18, 2026, highlighting it as part of broader WordPress theme security coverage (Wordfence Blog). Patchstack, which discovered and disclosed the vulnerability, classified it as high priority and noted its potential for use in mass-exploit campaigns targeting WordPress sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."