CVE-2025-53578
Published: 28 August 2025
Summary
CVE-2025-53578 is a high-severity PHP Remote File Inclusion (CWE-98) vulnerability. Its CVSS base score is 8.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 31.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).
Threat & Defense at a Glance
Threat & Defense Details
Mitigating Controls (NIST 800-53 r5)AI
Directly addresses the improper filename control in PHP include/require by requiring validation of user-supplied inputs to prevent local file inclusion.
Mandates timely remediation of the specific flaw in the gavias Kipso WordPress theme versions through 1.3.4 to eliminate the vulnerability.
Enforces secure configuration settings in PHP, such as disabling allow_url_include and open_basedir restrictions, to limit potential file inclusion exploits.
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
LFI vulnerability in public-facing WordPress theme directly enables remote exploitation of web application for initial access and arbitrary file/code inclusion.
NVD Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in gavias Kipso kipso allows PHP Local File Inclusion.This issue affects Kipso: from n/a through <= 1.3.4.
Deeper analysisAI
CVE-2025-53578 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, known as PHP Remote File Inclusion but enabling PHP Local File Inclusion, affecting the gavias Kipso WordPress theme. This issue impacts versions from n/a through 1.3.4 and was published on 2025-08-28. It is associated with CWE-98 and carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Unauthenticated remote attackers can exploit this vulnerability over the network, though it requires high attack complexity and no user interaction. Successful exploitation allows high-impact consequences, including unauthorized access to confidential data, modification of system integrity, and disruption of availability.
Mitigation details are available in the Patchstack advisory at https://patchstack.com/database/Wordpress/Theme/kipso/vulnerability/wordpress-kipso-theme-1-3-4-local-file-inclusion-vulnerability?_s_id=cve.
Details
- CWE(s)