Cyber Posture

CVE-2025-69081

High

Published: 07 January 2026

Published
07 January 2026
Modified
23 April 2026
KEV Added
Patch
CVSS Score 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0017 38.1th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0.

Mitigating Controls (NIST 800-53 r5)AI

prevent

Remediating the known flaw in the ThemeREX Hope WordPress theme up to version 3.0.0 directly prevents exploitation of this PHP local file inclusion vulnerability.

prevent

Validating filenames supplied to PHP include/require statements in the Hope theme blocks unauthorized local file inclusion by ensuring only legitimate paths are used.

detect

Vulnerability scanning identifies the presence of the vulnerable Hope theme, enabling timely remediation of this local file inclusion issue.

Security SummaryAI

CVE-2025-69081 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, known as PHP Remote File Inclusion, that enables PHP Local File Inclusion in the ThemeREX Hope (charity-is-hope) WordPress theme. This issue affects all versions of the Hope theme from n/a through 3.0.0 and is associated with CWE-98. The vulnerability was published on 2026-01-07 with a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Unauthenticated attackers with network access can exploit this vulnerability, though it requires high attack complexity and no user interaction. Successful exploitation allows high-impact compromise of confidentiality, integrity, and availability, potentially enabling attackers to include and execute arbitrary local PHP files on the server.

Mitigation details are available in the Patchstack advisory at https://patchstack.com/database/Wordpress/Theme/charity-is-hope/vulnerability/wordpress-hope-theme-3-0-0-local-file-inclusion-vulnerability?_s_id=cve.

Details

CWE(s)

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1005 Data from Local System Collection
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Why these techniques?

CVE-2025-69081 is a public-facing WordPress theme vulnerability (T1190) enabling local file inclusion for accessing data from the local system (T1005).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References