CVE-2025-60066
Published: 18 December 2025
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Katelyn katelyn allows PHP Local File Inclusion.This issue affects Katelyn: from n/a through <= 1.0.10.
Mitigating Controls (NIST 800-53 r5)AI
SI-10 requires validating inputs from external sources like HTTP parameters used in PHP include/require statements, directly preventing malicious filename manipulation leading to local file inclusion.
SI-2 mandates identifying, reporting, and correcting flaws such as this PHP file inclusion vulnerability through timely patching of the affected Katelyn theme.
CM-6 enforces secure configuration settings for PHP components, such as open_basedir restrictions or disabling allow_url_include, to limit the scope of local file inclusion exploits.
Security SummaryAI
CVE-2025-60066 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, classified as PHP Remote File Inclusion but enabling PHP Local File Inclusion, affecting the Katelyn WordPress theme developed by axiomthemes. The issue impacts all versions of Katelyn up to and including 1.0.10, as documented under CWE-98. Published on 2025-12-18, it carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Unauthenticated remote attackers (PR:N) can exploit this vulnerability over the network (AV:N) with high attack complexity (AC:H) and without requiring user interaction (UI:N). Successful exploitation allows attackers to achieve high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H), potentially enabling local file inclusion to read sensitive files, execute arbitrary code, or disrupt system operations on affected WordPress sites running the vulnerable theme.
The Patchstack advisory provides further details on this vulnerability in the Katelyn theme, available at https://patchstack.com/database/Wordpress/Theme/katelyn/vulnerability/wordpress-katelyn-theme-1-0-10-local-file-inclusion-vulnerability?_s_id=cve.
Details
- CWE(s)
Affected Products
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
The vulnerability is an LFI in a public-facing WordPress theme (T1190), enabling reading of sensitive local files (T1005, T1081) and arbitrary code execution.