Improper Control of Filename in InHype Blog & Magazine Theme by WordPress
CVE-2025-60199

8.2HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
6 November 2025

What is CVE-2025-60199?

The InHype - Blog & Magazine WordPress Theme contains a PHP Remote File Inclusion vulnerability, which allows for malicious manipulation of file inclusions. This flaw enables attackers to exploit how the theme handles filenames, potentially leading to unauthorized file access and execution on the server. Websites using InHype versions up to and including 1.5.2 are susceptible. It's essential for users to apply patches and updates to enhance their site's security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

InHype - Blog & Magazine WordPress Theme <= n/a

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program
.