CVE-2025-67515: WordPress Wilmër theme < 3.5 - Local File Inclusion vulnerability
Published Dec 9, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP Local File Inclusion.This issue affects Wilmër: from n/a through < 3.5.
Affected Software
3 affected components
Mikado-Themes Wilmër<3.5
WordPress Wilmër<3.5
Qodeinteractive Wilmer Wordpress<3.5
Event History
Dec 9, 2025
CVE Published
via MITRE·02:13 PM
Data Sourced
via MITRE·02:13 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:18 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67515?
CVE-2025-67515 is classified as a medium severity vulnerability due to the potential for local file inclusion attacks.
2
How do I fix CVE-2025-67515?
To fix CVE-2025-67515, upgrade the Mikado-Themes Wilmër to version 3.5 or higher.
3
What type of vulnerability is CVE-2025-67515?
CVE-2025-67515 is a PHP Remote File Inclusion vulnerability that allows for local file inclusion.
4
Which versions of Wilmër are affected by CVE-2025-67515?
CVE-2025-67515 affects all versions of Mikado-Themes Wilmër prior to 3.5.
5
What impact does CVE-2025-67515 have on my website?
The impact of CVE-2025-67515 includes the risk of unauthorized access to sensitive files on the server, which can compromise your website's security.