
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69005 is a PHP Local File Inclusion (LFI) vulnerability in the Elated-Themes "Search & Go" WordPress theme (plugin), classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of Search & Go through version 2.8. The vulnerability was published on January 22, 2026, by Patchstack, with CVSS v3.1 scoring added by CISA-ADP on January 28, 2026. It carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Patchstack).
The root cause is improper sanitization and validation of user-supplied input used in PHP include/require statements within the Search & Go theme, mapped to CWE-98. An unauthenticated remote attacker can manipulate filename parameters passed to these PHP file inclusion functions to include arbitrary local files from the server's filesystem. Exploitation requires high attack complexity (e.g., specific conditions or chaining with other vulnerabilities) but does not require authentication or user interaction. No public proof-of-concept code has been identified at this time (Feedly, Patchstack).
Successful exploitation could allow an attacker to read sensitive local files (e.g., WordPress wp-config.php containing database credentials), disclose confidential information, execute arbitrary PHP code if writable files or upload directories are accessible, and potentially achieve full server compromise. The vulnerability affects confidentiality, integrity, and availability at a high level, and could facilitate lateral movement within a hosting environment if credentials or configuration data are exposed (Feedly).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the latest available data. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. The attack vector is network-accessible and requires no authentication, but high attack complexity reduces immediate risk (Feedly).
include/require statement within the theme's codebase.../../../../wp-config.php or /etc/passwd) using path traversal sequences.wp-config.php) to gain further access to the WordPress admin panel, database, or hosting environment for full system compromise (Feedly).../, ..%2F, %2e%2e%2f) in query parameters or form fields.wp-config, passwd, or shadow./etc/passwd, wp-config.php) in server audit logs if file auditing is enabled.Update the Search & Go theme to a version newer than 2.8 immediately, as all versions through 2.8 are affected. If an updated version is not yet available or cannot be applied, consider disabling or removing the Search & Go theme/plugin to eliminate the attack surface. Additionally, implement a Web Application Firewall (WAF) rule to block path traversal patterns in HTTP requests as a compensating control. Review server file permissions to limit PHP's ability to read sensitive files outside the web root (Feedly, Patchstack).
The vulnerability was reported by Patchstack and noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report for the week of January 12–18, 2026. No significant broader media coverage or notable researcher commentary beyond standard vulnerability disclosure channels has been identified (Wordfence).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."