CVE-2025-68062: WordPress MinimogWP theme <= 3.9.6 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-68062?
CVE-2025-68062 has a high severity rating due to the potential for remote file inclusion, which can lead to serious security breaches.
How do I fix CVE-2025-68062?
To fix CVE-2025-68062, update the ThemeMove MinimogWP theme to the latest version beyond 3.9.6.
What are the potential risks associated with CVE-2025-68062?
The risks include unauthorized file access and potential execution of malicious code on the server, leading to data theft or system compromise.
Which versions of Minimog are affected by CVE-2025-68062?
CVE-2025-68062 affects MinimogWP versions from n/a through 3.9.6.
Is there a workaround for CVE-2025-68062 if I cannot update immediately?
A temporary workaround for CVE-2025-68062 may involve disabling the affected features or restricting file access until an update can be applied.