
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69076 is a PHP Local File Inclusion (LFI) vulnerability in the AncoraThemes Modern Housewife WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Modern Housewife theme from initial release through version 1.0.12. The vulnerability was reported by Patchstack and published on January 22, 2026. It carries a CVSS v3.1 base score of 8.1 (High), as assessed by CISA-ADP (NVD, Patchstack).
The root cause is improper sanitization and validation of user-supplied input used in PHP include or require statements within the Modern Housewife theme (CWE-98). An attacker can manipulate a filename parameter to cause the PHP interpreter to include arbitrary local files from the server's filesystem, potentially exposing sensitive configuration files or enabling code execution if attacker-controlled content exists on the server. The attack vector is network-based with high attack complexity, requiring no privileges or user interaction according to the CVSS assessment, though Feedly's executive summary notes that authenticated low-privilege access may be a precondition in practice. No public proof-of-concept exploit code has been identified (NVD, Patchstack).
Successful exploitation could allow an attacker to read sensitive files from the server (e.g., wp-config.php, /etc/passwd), modify application behavior, or execute malicious PHP code if attacker-controlled files are present on the server. This could result in full compromise of the WordPress installation, including unauthorized access to database credentials, user data, and site content. The confidentiality, integrity, and availability impacts are all rated High by CISA-ADP (NVD).
There is no known public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.0015 (0.15%), indicating a low probability of exploitation in the near term. No threat actor attribution has been reported (NVD, Patchstack).
No patch has been confirmed available for the Modern Housewife theme as of the time of disclosure. Organizations should immediately audit all WordPress installations using AncoraThemes Modern Housewife theme version 1.0.12 or earlier. If no update is available, consider disabling or replacing the theme. Restrict WordPress user account creation and authentication to trusted administrators only, and monitor PHP error logs and file access logs for suspicious include/require activity. Check the AncoraThemes vendor or WordPress theme repository for any available security updates (NVD, Patchstack).
The vulnerability was noted in the Wordfence Intelligence Weekly WordPress Vulnerability Report covering December 15, 2025 to January 4, 2026, and was also referenced in a CISA vulnerability summary for the week of January 19, 2026. No significant independent researcher commentary or broader media coverage has been identified beyond standard vulnerability aggregation (Wordfence Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."