
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68063 is a Local File Inclusion (LFI) vulnerability affecting the Splash - Sport Club WordPress Theme for Basketball, Football, Hockey by StylemixThemes, in versions 4.4.3 and earlier. The vulnerability requires a low-privileged (Contributor-level) authenticated attacker to exploit, and was published on June 26, 2026, with Patchstack as the assigning authority. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, Patchstack).
The vulnerability is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), which corresponds to PHP Remote/Local File Inclusion. An authenticated attacker with at least Contributor-level privileges can manipulate file path parameters to include arbitrary local files on the server. Exploitation requires high attack complexity, meaning specific conditions or knowledge of the target environment must be met, but no user interaction is needed beyond authentication (Feedly).
Successful exploitation of this LFI vulnerability can result in high confidentiality, integrity, and availability impacts on the affected WordPress installation. An attacker could read sensitive server files (e.g., configuration files containing database credentials), potentially escalate to remote code execution by including PHP-executable files, and disrupt site availability. The scope is limited to the affected system, but credential exposure could enable lateral movement to connected databases or services (Feedly).
include/require statement.../../../../wp-config.php) to include sensitive local files.wp-config.php for database credentials) or, if conditions allow, include a previously uploaded PHP file to achieve remote code execution (Feedly).../, %2e%2e%2f) in theme-related parameters; repeated requests to theme template or shortcode endpoints from a single Contributor account.wp-config.php, /etc/passwd, or other system files by the web server process.WordPress site administrators should update the Splash theme by StylemixThemes to a version beyond 4.4.3 as soon as a patched release is available from the vendor. In the interim, restricting Contributor-level user registration and auditing existing Contributor accounts can reduce the attack surface. Deploying a WordPress security plugin or Web Application Firewall (WAF) capable of detecting LFI patterns (e.g., Patchstack, Wordfence) is recommended as a compensating control (Patchstack).
The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the period of June 22–28, 2026, indicating routine tracking by the WordPress security community. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability database aggregation (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."