
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-67981 is a PHP Local File Inclusion (LFI) vulnerability in the thembay Besa WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Besa theme up to and including 2.3.15, allowing unauthenticated remote attackers to include and execute arbitrary local files on the server. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 8.1 (High) (Red Hat CVE).
The root cause is improper control of filename parameters passed to PHP include/require statements within the Besa theme (CWE-98), enabling local file inclusion. An unauthenticated remote attacker can manipulate filename input parameters to reference arbitrary files on the server's filesystem, causing the PHP interpreter to load and execute them. Exploitation requires high attack complexity (e.g., specific preconditions such as knowledge of file paths or the ability to upload a file), but no authentication or user interaction is needed. No public technical write-up or proof-of-concept code has been identified at this time (Red Hat CVE, Patchstack).
Successful exploitation can result in unauthorized disclosure of sensitive server files (e.g., configuration files containing credentials), execution of arbitrary PHP code, and full compromise of system integrity and availability. An attacker could read sensitive files such as wp-config.php, execute malicious code in the context of the web server process, and potentially pivot to broader system access or lateral movement within the hosting environment (Red Hat CVE).
No public proof-of-concept exploit or evidence of active in-the-wild exploitation has been observed as of the latest update (Red Hat CVE). The EPSS score is approximately 0.053%, indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high attack complexity, which reduces the immediate risk compared to simpler vulnerabilities.
Users should update the thembay Besa WordPress theme to a version newer than 2.3.15 if a patched release becomes available. In the interim, administrators should implement strict input validation and sanitization for all filename parameters used in PHP include/require statements, and apply a whitelist approach to restrict includable files. Deploying Web Application Firewall (WAF) rules to detect and block file inclusion attempts, and restricting web server file permissions, are recommended additional mitigations (Red Hat CVE).
The vulnerability was noted in a Wordfence Intelligence weekly WordPress vulnerability report covering the period of February 2–8, 2026, indicating routine tracking by the WordPress security community (Wordfence Blog). No significant vendor statements, researcher commentary, or broader media coverage have been identified beyond standard vulnerability database entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."