CVE-2025-68063
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-68063 is a Local File Inclusion (LFI) vulnerability affecting the Splash - Sport Club WordPress Theme for Basketball, Football, Hockey by StylemixThemes, in versions 4.4.3 and earlier. The vulnerability requires a low-privileged (Contributor-level) authenticated attacker to exploit, and was published on June 26, 2026, with Patchstack as the assigning authority. It carries a CVSS v3.1 base score of 7.5 (High) (Feedly, Patchstack).

Technical details

The vulnerability is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), which corresponds to PHP Remote/Local File Inclusion. An authenticated attacker with at least Contributor-level privileges can manipulate file path parameters to include arbitrary local files on the server. Exploitation requires high attack complexity, meaning specific conditions or knowledge of the target environment must be met, but no user interaction is needed beyond authentication (Feedly).

Impact

Successful exploitation of this LFI vulnerability can result in high confidentiality, integrity, and availability impacts on the affected WordPress installation. An attacker could read sensitive server files (e.g., configuration files containing database credentials), potentially escalate to remote code execution by including PHP-executable files, and disrupt site availability. The scope is limited to the affected system, but credential exposure could enable lateral movement to connected databases or services (Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Splash theme (version ≤ 4.4.3) by StylemixThemes, using tools like WPScan or by inspecting theme metadata in page source.
  2. Obtain Contributor Access: Register or compromise a Contributor-level account on the target WordPress site, as this is the minimum privilege required.
  3. Identify Vulnerable Parameter: Locate the theme functionality that accepts a file path or template parameter susceptible to LFI, likely within a shortcode, widget, or theme option processed by a PHP include/require statement.
  4. Craft LFI Payload: Submit a crafted request with a manipulated file path parameter (e.g., using path traversal sequences like ../../../../wp-config.php) to include sensitive local files.
  5. Exfiltrate Data or Escalate: Read the contents of included files (e.g., wp-config.php for database credentials) or, if conditions allow, include a previously uploaded PHP file to achieve remote code execution (Feedly).

Indicators of compromise

  • Logs: WordPress access logs showing requests with path traversal sequences (e.g., ../, %2e%2e%2f) in theme-related parameters; repeated requests to theme template or shortcode endpoints from a single Contributor account.
  • File System: Unexpected access to sensitive files such as wp-config.php, /etc/passwd, or other system files by the web server process.
  • Process: PHP error logs showing failed or successful file inclusion attempts referencing paths outside the theme directory.

Mitigation and workarounds

WordPress site administrators should update the Splash theme by StylemixThemes to a version beyond 4.4.3 as soon as a patched release is available from the vendor. In the interim, restricting Contributor-level user registration and auditing existing Contributor accounts can reduce the attack surface. Deploying a WordPress security plugin or Web Application Firewall (WAF) capable of detecting LFI patterns (e.g., Patchstack, Wordfence) is recommended as a compensating control (Patchstack).

Community reactions

The vulnerability was included in Wordfence's weekly WordPress vulnerability report for the period of June 22–28, 2026, indicating routine tracking by the WordPress security community. No notable individual researcher commentary or significant social media discussion has been identified beyond standard vulnerability database aggregation (Wordfence Blog).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-65562MEDIUM6.5
  • betterdocs
NoYesJul 27, 2026
CVE-2026-65563MEDIUM5.9
  • themeisle-companion
NoYesJul 27, 2026
CVE-2026-65557MEDIUM5.9
  • woocommerce-abandoned-cart
NoYesJul 27, 2026
CVE-2026-65567MEDIUM5.3
  • event-tickets
NoYesJul 27, 2026
CVE-2026-65568MEDIUM5
  • visualcomposer
NoYesJul 27, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management