CVE-2025-63074: WordPress The7 theme < 12.8.1.1 - Local File Inclusion vulnerability
Published Dec 9, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Dream-Theme The7 dt-the7 allows PHP Local File Inclusion.This issue affects The7: from n/a through < 12.8.1.1.
Affected Software
1 affected component
Dream-Theme The7<12.8.1.1
Event History
Dec 9, 2025
CVE Published
via MITRE·02:52 PM
Data Sourced
via MITRE·02:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-63074?
CVE-2025-63074 is classified as a high-severity vulnerability due to its potential for remote file inclusion.
2
How do I fix CVE-2025-63074?
To mitigate CVE-2025-63074, update Dream-Theme The7 to the latest version beyond 12.8.0.2.
3
What type of vulnerability is CVE-2025-63074?
CVE-2025-63074 is an Improper Control of Filename vulnerability that can lead to PHP Local File Inclusion.
4
Which versions of Dream-Theme The7 are affected by CVE-2025-63074?
All versions of Dream-Theme The7 prior to and including 12.8.0.2 are affected by CVE-2025-63074.
5
What impact does CVE-2025-63074 have on affected systems?
CVE-2025-63074 can allow attackers to execute arbitrary code on the server through local file inclusion.