CVE-2025-62045
Published: 06 November 2025
Summary
CVE-2025-62045 is a high-severity PHP Remote File Inclusion (CWE-98) vulnerability. Its CVSS base score is 8.1 (High).
Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 33.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).
Deeper analysis
CVE-2025-62045 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, classified as PHP Remote File Inclusion (CWE-98), affecting CodexThemes' TheGem Theme Elements (for WPBakery) plugin, known as thegem-elements, for WordPress. This issue impacts all versions from n/a through 5.10.5.1. Published on 2025-11-06, it carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), reflecting high severity due to its potential for significant impact.
Unauthenticated attackers with network access can exploit this vulnerability, though it requires high attack complexity and no user interaction. Successful exploitation enables high confidentiality, integrity, and availability impacts, allowing attackers to include and execute remote files, potentially leading to remote code execution on the targeted WordPress site.
The Patchstack advisory at https://patchstack.com/database/Wordpress/Plugin/thegem-elements/vulnerability/wordpress-thegem-theme-elements-for-wpbakery-plugin-5-10-5-1-local-file-inclusion-vulnerability?_s_id=cve documents the vulnerability and provides mitigation guidance for affected installations of the TheGem Theme Elements plugin up to version 5.10.5.1.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2025-38078
Vulnerability details
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CodexThemes TheGem Theme Elements (for WPBakery) thegem-elements.This issue affects TheGem Theme Elements (for WPBakery): from n/a through <= 5.10.5.1.
- CWE(s)
Related Threats
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
RFI vulnerability in public-facing WordPress plugin enables unauthenticated remote code execution via exploitation of public-facing application.
CVEs Like This One
Affected Assets
Mitigating Controls
Mitigating Controls (NIST 800-53 r5) AI
Timely patching of the vulnerable TheGem Theme Elements plugin up to version 5.10.5.1 directly remediates the PHP remote file inclusion flaw preventing RCE.
Validating inputs to PHP include/require statements in the WordPress plugin prevents attackers from supplying malicious remote filenames leading to file inclusion.
Establishing secure PHP configuration settings like allow_url_include=Off and open_basedir restrictions limits the ability to perform remote file inclusions even if the plugin flaw exists.