
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68985 is a Local File Inclusion (LFI) vulnerability in the Aora WordPress theme developed by thembay. It stems from improper control of filename parameters used in PHP include/require statements (CWE-98), allowing unauthenticated attackers to include arbitrary local files on the server. All versions of the Aora theme up to and including 1.3.15 are affected, and no official patch was available at the time of disclosure. The vulnerability was reported on December 20, 2025, and published on December 30, 2025, with a CVSS v3.1 base score of 9.8 (Critical) per NVD, though Patchstack assigns a score of 7.5 (High) with a low exploitation priority (Patchstack).
The vulnerability is classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), which enables PHP Local File Inclusion. The flaw exists because the Aora theme passes user-controlled input directly into PHP file inclusion functions without adequate sanitization or validation, allowing an attacker to manipulate the filename parameter to reference arbitrary files on the server. Exploitation requires Contributor or Developer-level privileges according to Patchstack, which somewhat limits the attack surface despite the high CVSS score assigned by NVD. The vulnerability was discovered and reported by researcher João Pedro S Alcântara (Kinorth) (Patchstack).
Successful exploitation of this LFI vulnerability could allow an attacker to read sensitive local files on the web server, including configuration files containing database credentials (e.g., wp-config.php), potentially leading to complete database compromise. Depending on server configuration, LFI vulnerabilities can also be chained with log poisoning or other techniques to achieve remote code execution. The confidentiality, integrity, and availability of the affected WordPress site are all at high risk if exploited (Patchstack).
As of disclosure, no public proof-of-concept exploit code or in-the-wild exploitation has been confirmed. The EPSS score is approximately 0.0015 (0.15%), indicating a low probability of exploitation in the near term. Patchstack classifies the priority as "Low," noting the vulnerability is unlikely to be exploited imminently, though it warns that similar LFI vulnerabilities are used in mass-exploit campaigns targeting WordPress sites. The vulnerability has been detected by Qualys (detection ID 530852) and is not listed in the CISA Known Exploited Vulnerabilities catalog (Patchstack).
include() or require() statement without proper sanitization.../../../../wp-config.php) targeting the vulnerable endpoint.wp-config.php to extract database credentials, secret keys, or other sensitive configuration data.../, ..%2F, %2e%2e%2f) in query parameters or POST body.wp-config.php, /etc/passwd, or server log files via the web process.No official patch from the theme vendor (thembay) was available at the time of disclosure for Aora versions ≤ 1.3.15. Site administrators should check for an updated version of the Aora theme and apply it immediately if available. As a workaround, consider replacing the theme with a patched alternative, restricting Contributor/Developer role assignments to trusted users only, and deploying a Web Application Firewall (WAF) such as Patchstack to virtually patch the vulnerability. Hosting providers or web developers should be consulted if an immediate upgrade is not feasible (Patchstack).
The vulnerability was covered in Wordfence's weekly WordPress vulnerability report for the period of December 15, 2025 to January 4, 2026, and noted by security aggregators including TheHackerWire on Mastodon and Bluesky. Qualys included it in their February 2026 application security detections publication. Community sentiment reflects routine concern about LFI vulnerabilities in WordPress themes, with no extraordinary attention given the low exploitation probability assigned by Patchstack (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."