Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Axiomthemes Crafti allows PHP Local File Inclusion. This issue affects Crafti: from n/a through 1.12.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2025-58705 is a PHP Local File Inclusion (LFI) vulnerability affecting Axiomthemes Crafti through version 1.12, stemming from improper control of filenames in include/require statements (CWE-98). This vulnerability allows attackers to manipulate file paths and read arbitrary files from the server's filesystem, potentially exposing sensitive configuration files, database credentials, or source code. WordPress site administrators using vulnerable versions of Crafti are at immediate risk, as LFI vulnerabilities can serve as initial footholds for more severe attacks, including remote code execution when combined with other techniques.
While this CVE currently maps to zero Casky skills, practitioners should understand that detection of LFI attack patterns typically involves monitoring for suspicious file path traversal attempts, unusual include/require statement parameters, and filesystem access anomalies. When mapped to MITRE ATT&CK, LFI techniques align with T1083 (File and Directory Discovery) and T1057 (Process Discovery). A security team leveraging Casky's Claude AI-powered analysis would examine web application logs for patterns like encoded traversal sequences (../, ..\), null byte injections, or wrapper protocols that indicate an attacker attempting to manipulate the include/require control flow. The extended reasoning capability would correlate these indicators with WordPress plugin behavior to distinguish malicious activity from legitimate application function, enabling faster incident response and vulnerability remediation.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2025-58705. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation