
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69410 is a PHP Local File Inclusion (LFI) vulnerability in the Edge-Themes Belletrist WordPress theme, classified under CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program). It affects all versions of the Belletrist theme up to and including version 1.2. The vulnerability was published on February 20, 2026, and carries a CVSS v3.1 base score of 8.1 (High) (Feedly, Wordfence).
The root cause is improper control of filename parameters used in PHP include/require statements within the Belletrist theme (CWE-98), which allows an attacker to manipulate file path inputs and cause the server to include arbitrary local files. The attack vector is network-based and requires no authentication or user interaction, though it is rated as high complexity, suggesting some precondition or constraint must be met (e.g., specific server configuration or parameter guessing). Exploitation follows the CAPEC-193 (PHP Remote File Inclusion) attack pattern, though in this case the confirmed impact is local file inclusion rather than remote (Feedly).
Successful exploitation could allow an unauthenticated remote attacker to read arbitrary local files accessible to the web server process, potentially exposing sensitive configuration files (e.g., wp-config.php), credentials, or other server-side data. Depending on server configuration and accessible files, the vulnerability may also enable code execution if files containing PHP code (such as uploaded files or log files) can be included. The confidentiality, integrity, and availability impacts are all rated High (Feedly).
There is no public proof-of-concept exploit available, and no evidence of active in-the-wild exploitation has been observed as of the latest update (Feedly). The EPSS score is approximately 0.053%, indicating a low current probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported.
/wp-content/themes/belletrist/style.css) or using tools like WPScan.../../../../wp-config.php) to reference a target local file.wp-config.php).../, ..%2F, %2e%2e%2f) in query parameters or POST body fields.wp-config.php, /etc/passwd, or server log files by the web server process.As of the disclosure date, no official patch has been released by Edge-Themes for the Belletrist theme (Feedly). Site administrators should consider the following interim measures: disable or remove the Belletrist theme and replace it with a patched alternative; implement Web Application Firewall (WAF) rules to detect and block path traversal and file inclusion attempts; restrict PHP file inclusion to a whitelist of allowed files at the application or server level; and monitor web server logs for suspicious file inclusion patterns. Contact Edge-Themes directly for patch availability or upgrade guidance.
Wordfence included CVE-2025-69410 in its weekly WordPress vulnerability report for the period of February 9–15, 2026, highlighting it as part of a broader set of theme-related vulnerabilities (Wordfence). No significant additional researcher commentary or media coverage has been identified beyond standard vulnerability database listings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."