PHP Local File Inclusion Issue in thembay Urna Theme
CVE-2025-67982

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
20 February 2026

What is CVE-2025-67982?

The thembay Urna theme is susceptible to a PHP Local File Inclusion vulnerability. This issue arises from improper control over the filename used in include or require statements. An attacker could exploit this flaw to include arbitrary files from the server, potentially leading to unauthorized access or manipulation of sensitive data. The vulnerability specifically impacts versions of the Urna theme running from its inception up to version 2.5.12, underscoring the need for users to implement immediate updates or patches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Urna <= n/a

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.