Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in androThemes Cookiteer allows PHP Local File Inclusion. This issue affects Cookiteer: from n/a through 1.4.8.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2025-68886 is a PHP Local File Inclusion (LFI) vulnerability affecting androThemes Cookiteer plugin versions through 1.4.8. The vulnerability stems from improper control of filenames in PHP include/require statements (CWE-98), allowing attackers to manipulate file path parameters and read arbitrary files from the server. This is particularly dangerous for WordPress sites using Cookiteer, as attackers can access sensitive configuration files (wp-config.php), database credentials, and other protected system files without authentication. The vulnerability affects all users of Cookiteer from inception through version 1.4.8, making it a widespread risk in the WordPress ecosystem.
While this CVE currently maps to zero Casky skills, practitioners defending against LFI attacks should focus on detection patterns related to Reconnaissance and Execution phases. Casky's Claude-powered analysis would identify suspicious file access patterns—such as unusual include/require parameters, path traversal sequences (../ patterns), or attempts to load files outside expected directories. Security teams would see findings flagged for suspicious parameter manipulation in WordPress plugin traffic, including encoded payloads attempting to access /etc/passwd, configuration files, or log files. Detection would center on monitoring POST/GET parameters passed to vulnerable Cookiteer functions for directory traversal indicators and implementing file inclusion whitelisting—techniques aligned with defense-in-depth approaches practitioners can implement while waiting for official patches to version 1.4.9 or later.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2025-68886. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation