Cyber Posture

CVE-2025-67935

High

Published: 08 January 2026

Published
08 January 2026
Modified
03 February 2026
KEV Added
Patch
CVSS Score 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0007 20.3th percentile
Risk Priority 16 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-67935 is a high-severity PHP Remote File Inclusion (CWE-98) vulnerability in Qodeinteractive Optimize. Its CVSS base score is 8.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 20.3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 RA-5 (Vulnerability Monitoring and Scanning) and SI-10 (Information Input Validation).

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploit Public-Facing Application (T1190). What defenders deploy: see the NIST 800-53 controls recommended below.
Threat & Defense Details

Mitigating Controls (NIST 800-53 r5)AI

prevent

Requires timely remediation of known software flaws, directly mitigating this PHP Local File Inclusion vulnerability by updating the Optimize WordPress theme to version 2.4 or later.

prevent

Enforces validation of user-supplied inputs at entry points, preventing malicious filenames from exploiting improper control in PHP include/require statements.

detect

Provides vulnerability scanning to identify the presence of this CVE-2025-67935 in deployed Optimize theme instances for subsequent remediation.

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Why these techniques?

Direct LFI in public-facing WordPress theme enables unauthenticated remote code execution via malicious local PHP file inclusion.

Confidence: HIGH · MITRE ATT&CK Enterprise v18.1

NVD Description

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4.

Deeper analysisAI

CVE-2025-67935 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, known as PHP Remote File Inclusion, that enables PHP Local File Inclusion in the Optimize WordPress theme (optimizewp) by Mikado-Themes. This issue affects all versions of the theme from n/a through those prior to 2.4. Published on 2026-01-08, it is associated with CWE-98 and carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

The vulnerability can be exploited by unauthenticated attackers with network access, requiring no user interaction but high attack complexity. Successful exploitation allows high-impact compromise of confidentiality, integrity, and availability, potentially enabling attackers to include and execute local PHP files on the server.

Advisories, including the Patchstack database entry at https://patchstack.com/database/Wordpress/Theme/optimizewp/vulnerability/wordpress-optimize-theme-2-4-local-file-inclusion-vulnerability?_s_id=cve, indicate mitigation through updating the Optimize theme to version 2.4 or later.

Details

CWE(s)

Affected Products

qodeinteractive
optimize
≤ 2.4

CVEs Like This One

CVE-2025-39466Same vendor: Qodeinteractive
CVE-2025-67937Same vendor: Qodeinteractive
CVE-2025-67936Same vendor: Qodeinteractive
CVE-2025-67934Same vendor: Qodeinteractive
CVE-2025-67515Same vendor: Qodeinteractive
CVE-2025-69034Same vendor: Qodeinteractive
CVE-2025-53334Shared CWE-98
CVE-2025-53567Shared CWE-98
CVE-2025-14475Shared CWE-98
CVE-2025-69076Shared CWE-98

References