
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68913 is a PHP Local File Inclusion (LFI) vulnerability in the Miion WordPress theme developed by zozothemes. It stems from improper control of filename parameters used in PHP include/require statements (CWE-98), allowing authenticated attackers to include arbitrary local files. All versions of the Miion theme up to and including 1.2.7 are affected. The vulnerability was published on January 22, 2026, by Patchstack, and carries a CVSS v3.1 base score of 7.5 (High) as assessed by CISA-ADP (Patchstack, NVD).
The root cause is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), where user-supplied input is passed unsanitized to a PHP include() or require() statement within the Miion theme. An attacker with low-privilege access (e.g., a subscriber-level WordPress account) can manipulate the filename parameter over the network to include arbitrary local files from the server's filesystem. Exploitation requires low privileges and high attack complexity, with no user interaction needed. No public proof-of-concept code has been identified at this time (Patchstack, NVD).
Successful exploitation allows an attacker to read sensitive local files on the server (e.g., WordPress configuration files containing database credentials, /etc/passwd), and potentially achieve remote code execution if file upload functionality or other writable paths can be leveraged in combination. The vulnerability carries high confidentiality, integrity, and availability impacts, meaning a fully compromised WordPress hosting environment is possible. Exposure of database credentials could further enable lateral movement to backend database systems (NVD, Patchstack).
No public exploit code or active in-the-wild exploitation has been reported for CVE-2025-68913 as of the available data. The EPSS score is approximately 0.053%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low-level authenticated access, which somewhat limits opportunistic mass exploitation but does not eliminate targeted risk (Feedly, NVD).
include() or require() call — typically exposed via a theme template, AJAX handler, or shortcode.../../../../wp-config.php or /etc/passwd, using path traversal sequences.wp-config.php) or other sensitive information.../, ..%2F, ....//) in parameters sent to WordPress theme endpoints; unusual GET/POST requests to theme-related AJAX handlers or template URLs.include()/require() calls.wp-config.php, /etc/passwd, or other configuration files; presence of web shells in writable directories if LFI is chained with file upload.The primary remediation is to update the Miion WordPress theme to a version beyond 1.2.7 that addresses this vulnerability. Site administrators should check the WordPress theme repository or the zozothemes vendor for a patched release. As an interim workaround, consider disabling the Miion theme and switching to an alternative, or restricting authenticated access to the WordPress site to trusted users only. Web application firewalls (WAFs) with rules targeting path traversal and LFI patterns can provide additional defense-in-depth (Patchstack, NVD).
The vulnerability was reported by Patchstack, a WordPress security platform, and was noted in Wordfence's weekly WordPress vulnerability report for the week of January 12–18, 2026. No significant broader media coverage or notable researcher commentary beyond these standard disclosure channels has been identified (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."