Local File Inclusion Vulnerability in Select-Themes Stockholm Theme
CVE-2025-68068

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
16 December 2025

What is CVE-2025-68068?

The Select-Themes Stockholm theme for WordPress is vulnerable to local file inclusion due to improper handling of the filename in PHP include/require statements. This vulnerability allows attackers to potentially include files from the local server, leading to the risk of malicious code execution or exposing sensitive information. The affected versions include Stockholm theme versions from n/a to 9.14.1, necessitating immediate action for users to safeguard their sites against potential exploitation.

Affected Version(s)

Stockholm <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

João Pedro S Alcântara (Kinorth) | Patchstack Bug Bounty Program
.
CVE-2025-68068 : Local File Inclusion Vulnerability in Select-Themes Stockholm Theme