CVE-2025-67530: WordPress Besa theme <= 2.3.15 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This issue affects Besa: from n/a through <= 2.3.15.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67530?
CVE-2025-67530 has been classified as a high severity vulnerability due to its potential for local file inclusion in PHP applications.
How do I fix CVE-2025-67530?
To fix CVE-2025-67530, update the Besa theme to version 2.3.16 or later as the vulnerability is patched in this release.
Which software is affected by CVE-2025-67530?
CVE-2025-67530 affects the WordPress Besa theme versions up to and including 2.3.15.
Can CVE-2025-67530 lead to remote code execution?
While CVE-2025-67530 primarily allows local file inclusion, it could potentially be exploited to execute arbitrary code if the attacker can manipulate the included files.
What are the risks associated with CVE-2025-67530?
The risks of CVE-2025-67530 include unauthorized access to sensitive files and potential broader attacks on the web server.