Cyber Resilience

CVE-2025-67935

High

Published: 08 January 2026

Published
08 January 2026
Modified
03 February 2026
KEV Added
Patch
CVSS Score v3.1 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0043 34.6th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2025-67935 is a high-severity PHP Remote File Inclusion (CWE-98) vulnerability in Qodeinteractive Optimize. Its CVSS base score is 8.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 34.6th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 RA-5 (Vulnerability Monitoring and Scanning) and SI-10 (Information Input Validation).

Deeper analysis

CVE-2025-67935 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, known as PHP Remote File Inclusion, that enables PHP Local File Inclusion in the Optimize WordPress theme (optimizewp) by Mikado-Themes. This issue affects all versions of the theme from n/a through those prior to 2.4. Published on 2026-01-08, it is associated with CWE-98 and carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

The vulnerability can be exploited by unauthenticated attackers with network access, requiring no user interaction but high attack complexity. Successful exploitation allows high-impact compromise of confidentiality, integrity, and availability, potentially enabling attackers to include and execute local PHP files on the server.

Advisories, including the Patchstack database entry at https://patchstack.com/database/Wordpress/Theme/optimizewp/vulnerability/wordpress-optimize-theme-2-4-local-file-inclusion-vulnerability?_s_id=cve, indicate mitigation through updating the Optimize theme to version 2.4 or later.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability details

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Direct LFI in public-facing WordPress theme enables unauthenticated remote code execution via malicious local PHP file inclusion.

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2025-39466Same vendor: Qodeinteractive
CVE-2025-69034Same vendor: Qodeinteractive
CVE-2025-67934Same vendor: Qodeinteractive
CVE-2025-67936Same vendor: Qodeinteractive
CVE-2025-67515Same vendor: Qodeinteractive
CVE-2025-67937Same vendor: Qodeinteractive
CVE-2025-58923Shared CWE-98
CVE-2025-69057Shared CWE-98
CVE-2024-54263Shared CWE-98
CVE-2026-28035Shared CWE-98

Affected Assets

qodeinteractive
optimize
≤ 2.4

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Requires timely remediation of known software flaws, directly mitigating this PHP Local File Inclusion vulnerability by updating the Optimize WordPress theme to version 2.4 or later.

prevent

Enforces validation of user-supplied inputs at entry points, preventing malicious filenames from exploiting improper control in PHP include/require statements.

detect

Provides vulnerability scanning to identify the presence of this CVE-2025-67935 in deployed Optimize theme instances for subsequent remediation.

References