CVE-2025-69314
Published: 22 January 2026
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in fuelthemes Werkstatt werkstatt allows PHP Local File Inclusion.This issue affects Werkstatt: from n/a through < 4.8.3.
Mitigating Controls (NIST 800-53 r5)AI
Directly remediates the PHP local file inclusion flaw in the Werkstatt theme by requiring timely patching to version 4.8.3 or later.
Enforces validation of filenames supplied to PHP include/require statements, preventing arbitrary local file inclusion attacks like this CVE.
Regular vulnerability scanning identifies the presence of this unpatched Werkstatt theme vulnerability (CVE-2025-69314) in WordPress environments.
Security SummaryAI
CVE-2025-69314, published on 2026-01-22, is an Improper Control of Filename for Include/Require Statement vulnerability in PHP programs, specifically a PHP Remote File Inclusion issue (CWE-98) that enables PHP Local File Inclusion. It affects the Werkstatt WordPress theme developed by fuelthemes, impacting all versions from n/a through those prior to 4.8.3. The vulnerability carries a CVSS v3.1 base score of 8.1 (High), with vector AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.
Remote attackers require no privileges or user interaction but must overcome high attack complexity to exploit the flaw over the network. Successful exploitation allows high-impact compromise of confidentiality, integrity, and availability, such as including and executing arbitrary local PHP files, potentially leading to server-side code execution.
The Patchstack advisory at https://patchstack.com/database/Wordpress/Theme/werkstatt/vulnerability/wordpress-werkstatt-theme-4-8-3-local-file-inclusion-vulnerability?_s_id=cve documents the local file inclusion vulnerability in the Werkstatt theme and associates mitigation with version 4.8.3.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
LFI vulnerability in public-facing WordPress theme enables remote exploitation of public-facing application (T1190) for arbitrary local file reads (T1005, T1083), facilitating access to sensitive files.