Cyber Resilience

CVE-2025-69081

High

Published: 07 January 2026

Published
07 January 2026
Modified
23 April 2026
KEV Added
Patch
CVSS Score v3.1 8.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0041 32.8th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2025-69081 is a high-severity PHP Remote File Inclusion (CWE-98) vulnerability. Its CVSS base score is 8.1 (High).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploit Public-Facing Application (T1190); ranked at the 32.8th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified are NIST 800-53 SI-10 (Information Input Validation) and SI-2 (Flaw Remediation).

Deeper analysis

CVE-2025-69081 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, known as PHP Remote File Inclusion, that enables PHP Local File Inclusion in the ThemeREX Hope (charity-is-hope) WordPress theme. This issue affects all versions of the Hope theme from n/a through 3.0.0 and is associated with CWE-98. The vulnerability was published on 2026-01-07 with a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).

Unauthenticated attackers with network access can exploit this vulnerability, though it requires high attack complexity and no user interaction. Successful exploitation allows high-impact compromise of confidentiality, integrity, and availability, potentially enabling attackers to include and execute arbitrary local PHP files on the server.

Mitigation details are available in the Patchstack advisory at https://patchstack.com/database/Wordpress/Theme/charity-is-hope/vulnerability/wordpress-hope-theme-3-0-0-local-file-inclusion-vulnerability?_s_id=cve.

OWASP Top 10 for Web (2025)

EU & UK References

Vulnerability details

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Hope charity-is-hope allows PHP Local File Inclusion.This issue affects Hope: from n/a through <= 3.0.0.

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

T1190 Exploit Public-Facing Application Initial Access
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
T1005 Data from Local System Collection
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior to Exfiltration.
Why these techniques?

CVE-2025-69081 is a public-facing WordPress theme vulnerability (T1190) enabling local file inclusion for accessing data from the local system (T1005).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2025-60057Shared CWE-98
CVE-2025-58940Shared CWE-98
CVE-2026-22476Shared CWE-98
CVE-2025-67980Shared CWE-98
CVE-2025-69034Shared CWE-98
CVE-2025-58225Shared CWE-98
CVE-2026-22427Shared CWE-98
CVE-2025-69402Shared CWE-98
CVE-2025-64205Shared CWE-98
CVE-2026-28013Shared CWE-98

Affected Assets

Mitigating Controls

Mitigating Controls (NIST 800-53 r5) AI

prevent

Remediating the known flaw in the ThemeREX Hope WordPress theme up to version 3.0.0 directly prevents exploitation of this PHP local file inclusion vulnerability.

prevent

Validating filenames supplied to PHP include/require statements in the Hope theme blocks unauthorized local file inclusion by ensuring only legitimate paths are used.

detect

Vulnerability scanning identifies the presence of the vulnerable Hope theme, enabling timely remediation of this local file inclusion issue.

References