Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Confidant allows PHP Local File Inclusion. This issue affects Confidant: from n/a through 1.4.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2025-53440 represents a critical PHP Local File Inclusion (LFI) vulnerability in Axiomthemes Confidant versions up to 1.4, stemming from improper control of filenames in include/require statements (CWE-98). This vulnerability allows attackers to include and execute arbitrary local files on the server, potentially exposing sensitive configuration files, source code, or triggering remote code execution when combined with file upload mechanisms. WordPress site administrators using the Confidant theme are directly affected, as the vulnerability can be exploited without authentication, making it a high-risk issue despite not yet appearing in CISA's actively exploited vulnerabilities list.
While this CVE lacks direct MITRE ATT&CK technique mappings, Casky's 754 security skills mapped to the framework can identify the attack patterns underlying LFI exploitation through detection of file access anomalies and suspicious include/require patterns. Practitioners using Casky would observe security findings related to techniques like T1083 (File and Directory Discovery) and T1190 (Exploit Public-Facing Application), as attackers typically probe for sensitive files through parameter manipulation. Extended reasoning capabilities would help correlate suspicious path traversal patterns (../, ..\) in web requests with actual file system access attempts, enabling defenders to distinguish legitimate include operations from exploitation attempts and implement targeted input validation controls before this vulnerability can be weaponized.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2025-53440. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation