CVE-2025-64195: WordPress Eduma theme <= 5.7.6 - Local File Inclusion vulnerability
Published Oct 29, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress Eduma eduma allows PHP Local File Inclusion.This issue affects Eduma: from n/a through <= 5.7.6.
Affected Software
2 affected components
thimpress Eduma<=5.7.6
WordPress Eduma theme<=5.7.6
Event History
Oct 29, 2025
CVE Published
via MITRE·08:38 AM
Data Sourced
via MITRE·08:38 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-64195?
CVE-2025-64195 has a critical severity rating due to its potential for remote file inclusion vulnerabilities.
2
How do I fix CVE-2025-64195?
To fix CVE-2025-64195, update the Eduma theme to the latest version that is beyond 5.7.6.
3
What does CVE-2025-64195 affect?
CVE-2025-64195 affects ThimPress Eduma versions up to and including 5.7.6.
4
What type of vulnerability is CVE-2025-64195?
CVE-2025-64195 is classified as a 'PHP Remote File Inclusion' vulnerability.
5
Can CVE-2025-64195 lead to data breaches?
Yes, CVE-2025-64195 may allow attackers to include malicious files, leading to potential data breaches.