CVE-2025-67934: WordPress Wellspring theme < 2.8 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wellspring wellspring allows PHP Local File Inclusion.This issue affects Wellspring: from n/a through < 2.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67934?
The severity of CVE-2025-67934 is classified as high due to the potential for local file inclusion vulnerabilities allowing unauthorized access to sensitive files.
How do I fix CVE-2025-67934?
To fix CVE-2025-67934, update the Mikado-Themes Wellspring theme to version 2.8 or later.
What are the potential impacts of CVE-2025-67934?
The potential impacts of CVE-2025-67934 include unauthorized access to local files and possible exposure of sensitive information.
Which versions are affected by CVE-2025-67934?
CVE-2025-67934 affects all versions of Mikado-Themes Wellspring and WordPress Wellspring prior to version 2.8.
Is CVE-2025-67934 a remote attack vector?
CVE-2025-67934 is not a remote attack vector but allows local file inclusion through improper control of the filename.