
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68902 is a Path Traversal (Arbitrary File Download) vulnerability in the AivahThemes Anona WordPress theme, affecting all versions up to and including 8.0. It was reported by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) on September 11, 2025, and publicly disclosed by Patchstack on January 13, 2026. The vulnerability carries a CVSS v3.1 base score of 7.5 (High), assigned by Patchstack, reflecting its unauthenticated, network-exploitable nature with high confidentiality impact (Patchstack, NVD).
The vulnerability is classified as CWE-22 (Improper Limitation of a Pathname to a Restricted Directory) and stems from insufficient validation of file path inputs within the Anona WordPress theme. An unauthenticated remote attacker can craft a malicious HTTP request that traverses outside the intended web root directory, enabling arbitrary file download from the server. No authentication or user interaction is required, and the attack complexity is low, making it trivially exploitable against any unpatched installation (Patchstack, NVD).
Successful exploitation allows an unauthenticated attacker to download arbitrary files from the affected WordPress server, including sensitive files such as wp-config.php (containing database credentials), backup archives, configuration files, and other data accessible to the web server process. This can lead to full credential compromise, enabling subsequent database access, administrative account takeover, and further lateral movement within the hosting environment (Patchstack).
No official patch is currently available for the Anona theme, leaving all installations on version 8.0 and below exposed. Patchstack notes that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting thousands of WordPress sites regardless of their traffic or popularity. The EPSS score is approximately 0.021% (0.000210), indicating a currently low but non-negligible probability of exploitation in the near term. No specific threat actor attribution or confirmed in-the-wild exploitation has been publicly reported, and the vulnerability does not appear in the CISA KEV catalog at this time (Patchstack, NVD).
../../../../wp-config.php or URL-encoded equivalents such as %2e%2e%2f) in the relevant parameter targeting sensitive files.wp-config.php with database credentials, secret keys, and salts).../, %2e%2e%2f, %252e%252e%252f) in query parameters or POST bodies targeting the Anona theme's endpoints; repeated requests for sensitive files such as wp-config.php from unexpected source IPs.No official patch from AivahThemes is currently available for the Anona theme. Patchstack has issued a virtual patch (mitigation rule) for Patchstack-protected sites to block exploitation attempts until an official fix is released. Site owners should consider removing or deactivating the Anona theme until a patched version is available, restricting web server access to sensitive files (e.g., via .htaccess rules blocking direct access to wp-config.php), and monitoring web server logs for path traversal patterns. Contacting the theme developer or hosting provider for assistance is also recommended (Patchstack).
Wordfence included this vulnerability in their weekly WordPress vulnerability intelligence report for the week of January 12–18, 2026, highlighting it as part of broader WordPress ecosystem security coverage. Patchstack, the discovering and reporting organization, classified it as high priority and noted its potential for use in mass-exploit campaigns. No significant independent researcher commentary or broader media coverage has been identified beyond these standard vulnerability disclosure channels.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."