CVE-2025-67935: WordPress Optimize theme < 2.4 - Local File Inclusion vulnerability
Published Jan 8, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Optimize optimizewp allows PHP Local File Inclusion.This issue affects Optimize: from n/a through < 2.4.
Affected Software
3 affected components
Mikado-Themes Optimize<2.4
WordPress Optimize<2.4
Qodeinteractive Optimize Wordpress<2.4
Event History
Jan 8, 2026
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67935?
CVE-2025-67935 is a high-severity vulnerability due to improper control of filename for include/require statements in the affected software.
2
How do I fix CVE-2025-67935?
To fix CVE-2025-67935, update Mikado-Themes Optimize to version 2.4 or later.
3
What types of vulnerabilities does CVE-2025-67935 involve?
CVE-2025-67935 involves PHP Remote File Inclusion and Local File Inclusion vulnerabilities.
4
Which versions of Mikado-Themes Optimize are affected by CVE-2025-67935?
CVE-2025-67935 affects Mikado-Themes Optimize versions up to but not including 2.4.
5
Is WordPress Optimize affected by CVE-2025-67935?
Yes, WordPress Optimize versions from launch through 2.4 are affected by CVE-2025-67935.