CVE-2025-67989
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-67989 is a Server-Side Request Forgery (SSRF) vulnerability in the LMPixels Kerge WordPress theme, affecting all versions up to and including 4.1.3. The vulnerability was reported by João Pedro S Alcântara (Kinorth) on November 22, 2025, and published by Patchstack on December 15–16, 2025. It carries a CVSS v3.1 base score of 5.4 (Medium), assigned by Patchstack (Patchstack).

Technical details

The vulnerability is classified as CWE-918 (Server-Side Request Forgery) and maps to OWASP Top 10 category A10: SSRF. It allows an unauthenticated attacker to cause the vulnerable WordPress site to issue HTTP requests to arbitrary domains or internal network resources controlled by the attacker. The attack vector is network-based, and while the Patchstack CNA CVSS vector indicates no user interaction is required (AV:N/AC:H/PR:N/UI:N/S:C), exploitation may vary depending on the specific theme functionality abused (Patchstack).

Impact

Successful exploitation could allow an attacker to cause the WordPress server to make requests to internal services or arbitrary external domains, potentially exposing sensitive information from services running on the same host or internal network (e.g., cloud metadata endpoints, internal APIs). The confidentiality and integrity impacts are rated as low, with no availability impact. The scope is noted as changed in the Patchstack CVSS vector, indicating potential for reaching resources beyond the vulnerable component itself (Patchstack).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported for this vulnerability. The EPSS score is approximately 0.017% (0.000170), indicating a very low probability of exploitation in the near term. Patchstack classifies this as low priority with no impactful threat, and it is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (Patchstack).

Mitigation and workarounds

The vulnerability is patched in Kerge theme version 4.1.4. Site administrators should update the Kerge theme to version 4.1.4 or later as the primary remediation. If an immediate update is not possible, consider restricting outbound HTTP requests from the web server at the network/firewall level as a temporary mitigation (Patchstack).

Community reactions

Wordfence included this vulnerability in its weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026, noting it as part of a broader set of WordPress theme and plugin vulnerabilities disclosed during that period (Wordfence). No significant additional vendor statements or notable researcher commentary beyond the Patchstack disclosure have been identified.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-18044NONEN/A
  • estatik
NoYesAug 12, 2026
CVE-2026-17008NONEN/A
  • quick-paypal-payments
NoNoAug 12, 2026
CVE-2026-16990NONEN/A
  • wp-paypal
NoNoAug 12, 2026
CVE-2026-16747NONEN/A
  • kirki
NoYesAug 12, 2026
CVE-2026-16621NONEN/A
  • woo-paypal-gateway
NoYesAug 12, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management