CVE-2025-69167
Deferred Deferred - Pending Action
Unauthenticated Local File Inclusion in Eros <= 1.3

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Unauthenticated Local File Inclusion in Eros <= 1.3 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
patchstack eros to 1.3 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-98 The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The vulnerability is an unauthenticated Local File Inclusion (LFI) issue found in the WordPress Eros Theme version 1.3 or lower. It allows attackers to include local files from the target website without needing to be authenticated.

This means an attacker can potentially access sensitive files on the server, such as database credentials, by exploiting this flaw.

Impact Analysis

This vulnerability can have a high impact as it allows attackers to access sensitive data stored on the server, including database credentials.

Such exposure can lead to further attacks, data breaches, and compromise of the website and its data.

Because the vulnerability can be exploited by unauthenticated users and is expected to be used in mass campaigns, it poses a significant risk to affected websites.

Mitigation Strategies

The vulnerability affects WordPress Eros Theme version 1.3 or lower and allows unauthenticated Local File Inclusion, which can expose sensitive data.

Immediate mitigation steps include updating the theme if an update is available or applying the mitigation rule provided by Patchstack to block attacks until an official fix is released.

It is also advised to seek assistance from your hosting provider or a developer to implement these mitigations effectively.

Compliance Impact

The vulnerability allows unauthenticated attackers to perform Local File Inclusion (LFI), potentially exposing sensitive data such as database credentials. Exposure of such sensitive information can lead to unauthorized access and data breaches.

This kind of data exposure can negatively impact compliance with common standards and regulations like GDPR and HIPAA, which require protection of personal and sensitive data. Failure to secure such data could result in violations of these regulations.

Immediate mitigation or patching is advised to reduce the risk of data exposure and maintain compliance.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-69167. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart