
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-6991 is a Local File Inclusion (LFI) vulnerability in the Kallyas theme for WordPress, affecting all versions up to and including 4.21.0. The flaw exists in the TH_LatestPosts4 widget and allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary PHP files on the server. It was published on July 26, 2025, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).
The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), with a secondary estimate of CWE-22 (Path Traversal). The TH_LatestPosts4 widget in the Kallyas theme fails to properly sanitize or restrict user-supplied input used in a PHP include or require statement, enabling an attacker to specify an arbitrary .php file path on the server. Exploitation requires the attacker to be authenticated at Contributor level or above, and is most impactful when the attacker can also upload .php files to the server (e.g., via another vulnerability or permitted upload functionality), enabling full remote code execution (Wordfence, ENISA EUVD).
Successful exploitation allows an authenticated attacker to execute arbitrary PHP code on the server, leading to full compromise of confidentiality, integrity, and availability. Attackers can bypass access controls, exfiltrate sensitive data (including WordPress database credentials, user data, and configuration files), and achieve remote code execution if they can upload a malicious PHP file. This could serve as a pivot point for lateral movement within the hosting environment or broader infrastructure (Wordfence, Red Hat CVE).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.066%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum Contributor-level authentication and high attack complexity, which limits opportunistic exploitation (Wordfence, ENISA EUVD).
TH_LatestPosts4 widget, which accepts user-controlled input that is passed to a PHP file inclusion function.TH_LatestPosts4 widget with unexpected file path parameters; PHP error logs referencing unexpected file inclusions..php files in the WordPress uploads directory or theme directories; newly created web shells or backdoor scripts.bash, curl, wget) following requests to Kallyas-themed pages.Users should update the Kallyas theme to a version beyond 4.21.0 as soon as a patched release is made available by the vendor (Hogash). In the interim, site administrators should restrict Contributor-level user registration and permissions, disable file uploads for untrusted roles, and use a WordPress security plugin (such as Wordfence) to detect and block exploitation attempts. Monitoring file system changes in the WordPress installation directory is also recommended (Wordfence, Wordfence Weekly Report).
Wordfence disclosed and assigned this CVE as part of their weekly WordPress vulnerability report for July 21–27, 2025, noting it as a notable LFI risk for sites using the Kallyas theme (Wordfence Weekly Report). The vulnerability was also noted by ZeroPath in a blog post summarizing related Kallyas theme RCE issues (ZeroPath Blog). No significant broader media coverage or notable researcher commentary beyond standard aggregator reporting has been observed.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."