CVE-2025-68544 - WordPress Diza theme <= 1.3.15 - local file inclusion vulnerability

CVE-2025-68544 - WordPress Diza theme <= 1.3.15 - local file inclusion vulnerability

CVE ID : CVE-2025-68544 Published : Dec. 23, 2025, 12:15 p.m. | 15 minutes ago Description : Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Thembay Diza allows PHP Local File Inclusion.This issue affects Diza: from n/a through 1.3.15. Severity: 7.5 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Dec. 23, 2025
Affected Product: PHP
Attack Vector: Local

Source: Telegram CVE Monitor