CVE-2025-67937: WordPress Hendon theme < 1.7 - Local File Inclusion vulnerability
Published Jan 8, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Hendon hendon allows PHP Local File Inclusion.This issue affects Hendon: from n/a through < 1.7.
Affected Software
3 affected components
Mikado-Themes Hendon<1.7
WordPress Hendon<1.7
Qodeinteractive Hendon Wordpress<1.7
Event History
Jan 8, 2026
CVE Published
via MITRE·09:17 AM
Data Sourced
via MITRE·09:17 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-67937?
CVE-2025-67937 is classified as a high severity vulnerability due to the risk of unauthorized file inclusion.
2
How do I fix CVE-2025-67937?
To fix CVE-2025-67937, update Mikado-Themes Hendon to version 1.7 or later.
3
What are the risks associated with CVE-2025-67937?
The risks of CVE-2025-67937 include the potential for attackers to execute arbitrary code on the server.
4
What software is affected by CVE-2025-67937?
CVE-2025-67937 affects Mikado-Themes Hendon versions prior to 1.7.
5
How can I determine if CVE-2025-67937 has been exploited?
To determine if CVE-2025-67937 has been exploited, check your server logs for unusual file access patterns or errors related to file inclusion.