
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68544 is a PHP Local File Inclusion (LFI) vulnerability in the Diza WordPress theme developed by Thembay. It stems from improper control of filenames in PHP include/require statements (CWE-98), allowing authenticated attackers to include arbitrary local files on the server. All versions of the Diza theme through 1.3.15 are affected. The vulnerability was published on December 23, 2025, and assigned by Patchstack. It carries a CVSS v3.1 base score of 7.5 (High) (Patchstack, Red Hat CVE).
The root cause is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is passed unsanitized to a PHP include() or require() statement within the Diza theme. An authenticated attacker with low privileges can manipulate the filename parameter to traverse the file system and include arbitrary local files, potentially exposing sensitive server-side files such as configuration files, credentials, or other PHP scripts. The attack vector is network-based, requires low privileges, no user interaction, and has high attack complexity. No public proof-of-concept exploit code has been identified at this time (Patchstack, Red Hat CVE).
Successful exploitation of this LFI vulnerability can result in high impact to confidentiality, integrity, and availability of the affected WordPress installation. An attacker could read sensitive files (e.g., wp-config.php containing database credentials), potentially escalate to remote code execution by including log files or uploaded PHP content, and disrupt site availability. The scope is limited to the affected system, but credential exposure could enable lateral movement to the underlying database or hosting infrastructure (Patchstack, Red Hat CVE).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-68544 as of the available data. The EPSS score is approximately 0.127%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires authenticated access (low privilege), which somewhat limits the attack surface compared to unauthenticated vulnerabilities (Red Hat CVE, Feedly).
include() or require() statement within the Diza theme codebase.../../../../wp-config.php or /etc/passwd) in the vulnerable parameter to force the server to include an arbitrary local file.wp-config.php, which can be used for further compromise (Patchstack).../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.wp-config.php, /etc/passwd, or PHP log files.wp-config.php or system files that do not correspond to normal application activity.The primary remediation is to update the Diza WordPress theme to a version beyond 1.3.15 if a patched release becomes available from Thembay. Site administrators should monitor the official theme repository and Patchstack advisories for patch availability. As an interim workaround, consider restricting access to the WordPress site to trusted users only, disabling user registration if not required, and deploying a Web Application Firewall (WAF) with rules to detect and block path traversal attempts. Removing or replacing the Diza theme with an actively maintained alternative is advisable if no patch is released promptly (Patchstack, Red Hat CVE).
The vulnerability was reported and assigned by Patchstack, which disclosed it on December 23, 2025. Wordfence included it in their weekly WordPress vulnerability report covering December 15, 2025 to January 4, 2026 (Wordfence). General community coverage has been limited to automated vulnerability aggregators and security feeds, with no notable researcher commentary or significant social media discussion identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."