CVE-2025-60069: WordPress MinimogWP theme <= 3.9.6 - Local File Inclusion vulnerability
Published Dec 18, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6.
Affected Software
2 affected components
wordpress/minimogwp<=3.9.6
ThemeMove Minimogwp Wordpress<=3.9.6
Event History
Dec 18, 2025
CVE Published
via MITRE·07:22 AM
Data Sourced
via MITRE·07:22 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60069?
The severity of CVE-2025-60069 is considered high due to the potential for remote file inclusion leading to code execution.
2
How do I fix CVE-2025-60069?
To fix CVE-2025-60069, update the MinimogWP theme to the latest version beyond 3.9.6.
3
What version of MinimogWP is affected by CVE-2025-60069?
CVE-2025-60069 affects all versions of MinimogWP from n/a through 3.9.6 inclusive.
4
What types of attacks can CVE-2025-60069 facilitate?
CVE-2025-60069 can facilitate remote file inclusion attacks, allowing attackers to execute arbitrary code.
5
Is CVE-2025-60069 related to WordPress?
Yes, CVE-2025-60069 is a vulnerability in the MinimogWP theme used in WordPress installations.