Junglewise Threat Intelligence

CVE-2025-68064: Everthemess Goya Core Local File Inclusion in WordPress plugin

CVE-2025-68064 · Severity: high · CVSS 7.5 · Published 2026-06-26

Executive brief

Goya Core is a WordPress plugin used to provide core functionality for the Goya theme. A security flaw allows users with 'Contributor' level access to view sensitive files on the web server. This could lead to the exposure of database credentials or other configuration files, potentially allowing an attacker to take full control of the website.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Goya Core plugin for WordPress (versions prior to 1.0.9.4) due to improper control of filenames in PHP include/require statements (CWE-98). An attacker with 'Contributor' or higher privileges can exploit this flaw to include and execute local files on the server. While the attack complexity is rated as high, successful exploitation could allow an attacker to read sensitive files like wp-config.php, leading to the exposure of database credentials and potential full system compromise. The issue is resolved in version 1.0.9.4.

Affected products

  • Everthemess Goya Core < 1.0.9.4

Timeline

  • 2025-10-31: other: Reported by researcher João Pedro S Alcântara (Kinorth)
  • 2026-06-26: patched: Patch released and vulnerability disclosed by Patchstack

References