
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67946 is a Local File Inclusion (LFI) vulnerability in the AdForest WordPress theme developed by scriptsbundle, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all AdForest theme versions up to and including 6.0.11, with version 6.0.12 being the patched release. The vulnerability was reported on November 4, 2025, by researcher João Pedro S Alcântara (Kinorth), published by Patchstack on January 20, 2026, and assigned a CVSS v3.1 base score of 8.1 (High) (Patchstack, NVD).
The root cause is improper sanitization and validation of filename parameters used in PHP include/require statements within the AdForest theme (CWE-98). An unauthenticated remote attacker can manipulate file path parameters in HTTP requests to cause the server to include arbitrary local files, potentially exposing their contents. The attack vector is network-based, requires no user interaction or privileges, but carries high attack complexity. The vulnerability is mapped to CAPEC-193 (PHP Remote File Inclusion) and was disclosed via Patchstack's vulnerability database (Patchstack, NVD).
Successful exploitation allows an attacker to include and execute arbitrary local files on the WordPress server, potentially exposing sensitive data such as database credentials stored in configuration files (e.g., wp-config.php). This could lead to full database compromise, information disclosure, and — depending on server configuration and accessible files — remote code execution. All three security pillars (confidentiality, integrity, and availability) are rated as HIGH impact (Patchstack).
style.css files.../../../../wp-config.php or /etc/passwd).wp-config.php) to gain further access to the database or WordPress admin panel, enabling full site compromise (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters or POST body targeting AdForest theme endpoints.wp-config.php, /etc/passwd, or /etc/shadow.wp-config.php or system files that do not correspond to legitimate administrative activity.The primary remediation is to update the AdForest theme to version 6.0.12 or later, which contains the fix for this vulnerability (Patchstack). As an interim measure, Patchstack has issued a virtual patch/mitigation rule for subscribers to block exploitation attempts until the theme is updated. Additional hardening steps include: ensuring PHP's allow_url_include is set to Off in php.ini, implementing strict input validation on all file inclusion parameters, and restricting file system permissions to limit accessible files. Web application firewall (WAF) rules targeting path traversal patterns can also reduce exposure.
Wordfence included this vulnerability in their weekly WordPress vulnerability report covering January 19–25, 2026, highlighting it as part of broader WordPress ecosystem security monitoring (Wordfence). Patchstack, which discovered and disclosed the vulnerability, classified it as high priority and noted its potential for use in mass-exploit campaigns against WordPress sites regardless of traffic size or popularity (Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."