CVE-2025-67981
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67981 is a PHP Local File Inclusion (LFI) vulnerability in the thembay Besa WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Besa theme up to and including 2.3.15, allowing unauthenticated remote attackers to include and execute arbitrary local files on the server. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 8.1 (High) (Red Hat CVE).

Technical details

The root cause is improper control of filename parameters passed to PHP include/require statements within the Besa theme (CWE-98), enabling local file inclusion. An unauthenticated remote attacker can manipulate filename input parameters to reference arbitrary files on the server's filesystem, causing the PHP interpreter to load and execute them. Exploitation requires high attack complexity (e.g., specific preconditions such as knowledge of file paths or the ability to upload a file), but no authentication or user interaction is needed. No public technical write-up or proof-of-concept code has been identified at this time (Red Hat CVE, Patchstack).

Impact

Successful exploitation can result in unauthorized disclosure of sensitive server files (e.g., configuration files containing credentials), execution of arbitrary PHP code, and full compromise of system integrity and availability. An attacker could read sensitive files such as wp-config.php, execute malicious code in the context of the web server process, and potentially pivot to broader system access or lateral movement within the hosting environment (Red Hat CVE).

Exploitability

No public proof-of-concept exploit or evidence of active in-the-wild exploitation has been observed as of the latest update (Red Hat CVE). The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high attack complexity, which reduces the immediate risk compared to simpler vulnerabilities.

Mitigation and workarounds

Users should update the thembay Besa WordPress theme to a version newer than 2.3.15 if a patched release becomes available. In the interim, administrators should implement strict input validation and sanitization for all filename parameters used in PHP include/require statements, and apply a whitelist approach to restrict includable files. Deploying Web Application Firewall (WAF) rules to detect and block file inclusion attempts, and restricting web server file permissions, are recommended additional mitigations (Red Hat CVE).

Community reactions

The vulnerability was noted in a Wordfence Intelligence weekly WordPress vulnerability report covering the period of February 2–8, 2026, indicating routine tracking by the WordPress security community (Wordfence Blog). No significant vendor statements, researcher commentary, or broader media coverage have been identified beyond standard vulnerability database entries.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-83547MEDIUM6.8
  • xpro-elementor-addons
NoYesSep 02, 2026
CVE-2026-82884MEDIUM6.8
  • all-in-one-seo-pack
NoYesSep 02, 2026
CVE-2026-8151MEDIUM5.4
  • simple-membership-mailchimp-integration
NoYesSep 02, 2026
CVE-2026-83533MEDIUM5.3
  • wp-express-checkout
NoYesSep 02, 2026
CVE-2026-81571MEDIUM4.8
  • brave-popup-builder
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management