CVE-2025-69408: WordPress HealthFirst theme <= 1.0.1 - Local File Inclusion vulnerability
Published Feb 20, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes HealthFirst healthfirst allows PHP Local File Inclusion.This issue affects HealthFirst: from n/a through <= 1.0.1.
Affected Software
2 affected components
Mikado-Themes HealthFirst<=1.0.1
WordPress HealthFirst theme<=1.0.1
Event History
Feb 20, 2026
CVE Published
via MITRE·03:46 PM
Data Sourced
via MITRE·03:46 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-69408?
CVE-2025-69408 is categorized as a high severity local file inclusion vulnerability.
2
How do I fix CVE-2025-69408?
To fix CVE-2025-69408, update the HealthFirst theme to version 1.0.2 or later.
3
What systems are affected by CVE-2025-69408?
CVE-2025-69408 affects the Mikado-Themes HealthFirst theme version 1.0.1 or earlier.
4
What kind of attack can CVE-2025-69408 enable?
CVE-2025-69408 can enable remote attackers to execute arbitrary PHP code through local file inclusion.
5
Is CVE-2025-69408 an isolated vulnerability?
CVE-2025-69408 is specific to the HealthFirst theme and does not affect other WordPress themes or plugins.