CVE-2025-6991
WordPress vulnerability analysis and mitigation

Overview

CVE-2025-6991 is a Local File Inclusion (LFI) vulnerability in the Kallyas theme for WordPress, affecting all versions up to and including 4.21.0. The flaw exists in the TH_LatestPosts4 widget and allows authenticated attackers with Contributor-level access or higher to include and execute arbitrary PHP files on the server. It was published on July 26, 2025, and assigned by Wordfence. The vulnerability carries a CVSS v3.1 base score of 7.5 (High) (Wordfence, Red Hat CVE).

Technical details

The root cause is classified as CWE-98 (Improper Control of Filename for Include/Require Statement in PHP Program), with a secondary estimate of CWE-22 (Path Traversal). The TH_LatestPosts4 widget in the Kallyas theme fails to properly sanitize or restrict user-supplied input used in a PHP include or require statement, enabling an attacker to specify an arbitrary .php file path on the server. Exploitation requires the attacker to be authenticated at Contributor level or above, and is most impactful when the attacker can also upload .php files to the server (e.g., via another vulnerability or permitted upload functionality), enabling full remote code execution (Wordfence, ENISA EUVD).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary PHP code on the server, leading to full compromise of confidentiality, integrity, and availability. Attackers can bypass access controls, exfiltrate sensitive data (including WordPress database credentials, user data, and configuration files), and achieve remote code execution if they can upload a malicious PHP file. This could serve as a pivot point for lateral movement within the hosting environment or broader infrastructure (Wordfence, Red Hat CVE).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported as of the disclosure date. The EPSS score is approximately 0.066%, indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires at minimum Contributor-level authentication and high attack complexity, which limits opportunistic exploitation (Wordfence, ENISA EUVD).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites using the Kallyas theme (version ≤ 4.21.0) via HTTP response headers, page source, or tools like WPScan.
  2. Obtain Contributor Access: Register or compromise a Contributor-level (or higher) WordPress account on the target site.
  3. Identify the vulnerable widget: Locate a page or post using the TH_LatestPosts4 widget, which accepts user-controlled input that is passed to a PHP file inclusion function.
  4. Upload a malicious PHP file (if possible): Use any available file upload mechanism (e.g., media upload with a misconfigured server, or another vulnerability) to place a PHP web shell on the server.
  5. Trigger LFI: Craft a request or widget configuration that supplies the path to the uploaded malicious PHP file as the inclusion target, causing the server to include and execute it.
  6. Achieve code execution: The included PHP file executes with the web server's privileges, enabling command execution, data exfiltration, or further persistence (Wordfence).

Indicators of compromise

  • Logs: WordPress access logs showing unusual POST or GET requests to pages using the TH_LatestPosts4 widget with unexpected file path parameters; PHP error logs referencing unexpected file inclusions.
  • File System: Presence of unexpected .php files in the WordPress uploads directory or theme directories; newly created web shells or backdoor scripts.
  • Process: Unusual child processes spawned by the web server process (e.g., bash, curl, wget) following requests to Kallyas-themed pages.
  • Network: Outbound connections from the web server to unknown external IPs following exploitation attempts.

Mitigation and workarounds

Users should update the Kallyas theme to a version beyond 4.21.0 as soon as a patched release is made available by the vendor (Hogash). In the interim, site administrators should restrict Contributor-level user registration and permissions, disable file uploads for untrusted roles, and use a WordPress security plugin (such as Wordfence) to detect and block exploitation attempts. Monitoring file system changes in the WordPress installation directory is also recommended (Wordfence, Wordfence Weekly Report).

Community reactions

Wordfence disclosed and assigned this CVE as part of their weekly WordPress vulnerability report for July 21–27, 2025, noting it as a notable LFI risk for sites using the Kallyas theme (Wordfence Weekly Report). The vulnerability was also noted by ZeroPath in a blog post summarizing related Kallyas theme RCE issues (ZeroPath Blog). No significant broader media coverage or notable researcher commentary beyond standard aggregator reporting has been observed.

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16145HIGH7.2
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026
CVE-2026-18387MEDIUM6.5
  • groundhogg
NoYesAug 15, 2026
CVE-2026-16586MEDIUM6.5
  • contest-gallery
NoYesAug 15, 2026
CVE-2026-17090MEDIUM6.4
  • beaver-builder-lite-version
NoYesAug 15, 2026
CVE-2026-16146MEDIUM4.9
  • gdpr-compliant-recaptcha-for-all-forms
NoYesAug 15, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management