CVE-2025-67981: WordPress Besa theme <= 2.3.15 - Local File Inclusion vulnerability
Published Feb 20, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This issue affects Besa: from n/a through <= 2.3.15.
Affected Software
1 affected component
WordPress Besa<=2.3.15
Event History
Feb 20, 2026
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-67981?
CVE-2025-67981 has a severity rating of high with a CVSS score of 8.1.
2
How do I fix CVE-2025-67981?
To fix CVE-2025-67981, update the WordPress Besa theme to version 2.3.16 or later.
3
What type of vulnerability is CVE-2025-67981?
CVE-2025-67981 is a Local File Inclusion vulnerability allowing improper control of filename for PHP include statements.
4
Which versions of the Besa theme are affected by CVE-2025-67981?
CVE-2025-67981 affects Besa theme versions n/a through 2.3.15.
5
What are the potential impacts of CVE-2025-67981?
The potential impacts of CVE-2025-67981 include unauthorized access to sensitive files, which may lead to data exposure or system compromise.