CVE-2025-69160
Deferred Deferred - Pending Action
Unauthenticated Local File Inclusion in Gita

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Unauthenticated Local File Inclusion in Gita <= 1.11 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack gita to 1.11 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-98 The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2025-69160 is a Local File Inclusion (LFI) vulnerability found in the WordPress Gita Theme versions 1.11 and below.

This flaw allows unauthenticated attackers to include local files on the target website, which can lead to exposure of sensitive data such as database credentials.

In some configurations, this vulnerability can even result in a complete database takeover.

There is currently no official patch available, but temporary mitigation rules have been issued to block attacks until a fix is released.

Impact Analysis

This vulnerability poses a high risk with a CVSS score of 8.1, meaning it can have a severe impact on affected websites.

  • Exposure of sensitive data such as database credentials.
  • Potential complete takeover of the website's database in certain configurations.
  • Increased risk of being targeted in mass-exploit campaigns.

Overall, this can lead to data breaches, loss of control over the website, and significant security incidents.

Mitigation Strategies

The vulnerability affects WordPress Gita Theme versions 1.11 and below and allows unauthenticated attackers to include local files, potentially exposing sensitive data.

As there is no official patch available yet, immediate mitigation involves applying the temporary mitigation rule issued by Patchstack to block attacks.

Additional recommended steps include updating the theme when a patch becomes available or seeking assistance from your hosting provider or developer.

Compliance Impact

The vulnerability allows unauthenticated attackers to include local files on the target website, potentially exposing sensitive data such as database credentials and enabling complete database takeover in some cases.

Exposure of sensitive data due to this vulnerability could lead to non-compliance with data protection regulations like GDPR and HIPAA, which require safeguarding personal and sensitive information against unauthorized access.

Therefore, organizations using the affected versions of the Gita theme may face increased risk of violating these standards if the vulnerability is exploited.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-69160. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart