CVE-2025-54701·PHP vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Unicamp unicamp allows PHP Local File Inclusion.This issue affects Unicamp: from n/a through <= 2.6.3.
- Severity
- high
- Software
- PHP
- Fixed in
- 2.6.4
- Published
- 2025-08-14
Affected versions
Until: 2.6.4
Fixed in: 2.6.4
How to fix this CVE
Update the ThemeMove Unicamp WordPress theme to version 2.6.4 or later to patch the local file inclusion vulnerability that allows unauthenticated attackers to read sensitive files from your server. If you are running PHP with the vulnerable Unicamp theme installed, apply the update immediately and verify the installation by checking the theme version in your WordPress admin panel. This vulnerability requires immediate remediation as it can expose database credentials, configuration files, and other sensitive data.
sudo dnf update php -yDefensia detects this vulnerability
What an exploitation attempt looks like
Sample log line indicative of exploitation attempts:
GET|POST requests containing path traversal sequences (../ or ..\) in query parameters or POST data targeting PHP include/require functions; example patterns: (?:\.\./)+(?:etc/passwd|wp-config\.php|wp-settings\.php) or similar file inclusion attempts in URI or bodyWAF mitigation (if patching is not yet possible)
Add this rule to your WAF to block exploitation attempts while you schedule the patch.
Implement a WAF rule that blocks HTTP requests containing path traversal patterns (../ or ..\ sequences) in query strings and POST parameters. Additionally, restrict access to sensitive PHP files and configuration files by denying requests that attempt to include files outside the intended WordPress theme directory.How to check if you are affected
- Check the installed PHP version: php -v
- Verify the Unicamp theme version by navigating to Appearance > Themes in WordPress admin, or by running: grep -r 'Version:' /path/to/wp-content/themes/unicamp/style.css
- Search web server logs for suspicious file inclusion patterns: grep -E '\.\./' /var/log/apache2/access.log or grep -E '\.\./' /var/log/nginx/access.log
- Confirm the fix by re-checking the Unicamp theme version after update; it should display 2.6.4 or higher
FAQ
What is CVE-2025-54701?
CVE-2025-54701 is a local file inclusion (LFI) vulnerability in the ThemeMove Unicamp WordPress theme versions up to 2.6.3 that allows an unauthenticated attacker to read arbitrary files from the affected web server by manipulating include/require file paths.
Is CVE-2025-54701 being actively exploited?
No, CVE-2025-54701 is not currently listed on the CISA Known Exploited Vulnerabilities catalog, and there are no publicly available exploit proofs-of-concept at this time. However, the attack requires no authentication or user interaction, making it a significant risk.
What versions of PHP and Unicamp are affected by CVE-2025-54701?
The Unicamp WordPress theme versions through 2.6.3 are vulnerable. The vulnerability is patched in version 2.6.4 and later. This affects sites running any version of PHP that supports WordPress.
How do I check if my server is vulnerable to CVE-2025-54701?
Log into your WordPress admin panel, go to Appearance > Themes, and check if Unicamp is installed with a version number ≤ 2.6.3. Alternatively, run: grep 'Version:' /var/www/html/wp-content/themes/unicamp/style.css
Does Defensia detect CVE-2025-54701?
Yes — Defensia's CVE advisory scanner compares installed package versions against the NVD database. If the Unicamp theme or PHP is installed on a monitored server, CVE-2025-54701 will appear in your dashboard with remediation steps.
Related PHP CVEs
References
Track CVEs across your fleet automatically
Defensia scans your Linux servers and tells you exactly which ones are running vulnerable versions — including CVE-2025-54701. Free for 1 server.
Get started free