External risk intelligence

Goza WordPress Theme Arbitrary File Deletion Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-10134

The vulnerability affects a WordPress theme. WordPress themes are components of web applications that are typically deployed as public-facing websites. Because the theme functionality is exposed via the web server, it is commonly reachable from the internet in standard deployments.

Remote Code Execution

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This critical vulnerability in a WordPress theme could allow unauthenticated attackers to delete any file on the server, potentially leading to complete system compromise. The primary concern is to confirm if this theme is in use and if it is exposed to external access.

  • Theme flaw allows attackers to delete server files.
  • Critical flaw can lead to full system takeover.
  • Confirm theme use and external exposure.

Attack Path

How an attacker could exploit the issue

An attacker can delete arbitrary files on a WordPress server without logging in, potentially leading to remote code execution. This is possible because the theme fails to properly check the paths of files it is asked to delete. If an attacker can trick the theme into deleting a critical configuration file, such as the WordPress configuration file, they could gain control of the website.

  • No authentication needed.
  • Triggered by file deletion request.
  • Risk of remote code execution.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could delete arbitrary files on the server when the Goza - Nonprofit Charity WordPress Theme is used. This could lead to remote code execution if critical files such as `wp-config.php` are deleted.

  • Arbitrary file deletion on the server.
  • Insufficient path validation allows file deletion.
  • Remote code execution can occur.

Operational Fix

Recommended remediation, mitigation, and detection steps

The Goza WordPress theme's arbitrary file deletion vulnerability requires immediate attention from application owners and the infrastructure team responsible for the WordPress deployment. The first practical step is to identify all instances of the Goza theme, confirm their reachability and criticality, and then assign ownership for remediation planning based on risk.

  • Application owners should prioritize this.
  • Verify all Goza theme instances.
  • Plan remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Goza WordPress theme?

Goza is a WordPress theme designed for nonprofit and charity websites. It controls the visual layout and user experience of a site built on the WordPress platform. Like other themes, it functions as a component of the website, running on the server to render pages to visitors and manage specific site features.

What does CVE-2025-10134 mean?

This CVE refers to an arbitrary file deletion vulnerability, classified as CWE-73 (External Control of File Name or Path). It means the theme fails to properly validate the file paths it processes. Because of this flaw, an attacker can manipulate the software to delete specific files stored on the server that the website relies on to function.

How is the Goza vulnerability triggered?

The flaw is triggered when an attacker sends a crafted request to the specific function responsible for importing or restoring data. Authentication is not required, meaning the attacker does not need a user account. Simply browsing the site or performing normal, non-administrative actions will not trigger this bug; it requires specific interaction with the vulnerable theme function.

Do I need to worry about this vulnerability?

Yes, if you use the Goza theme. Halo Surface Signal identifies this as a likely risk because WordPress themes are typically deployed on public-facing web servers. Since the vulnerability is reachable over the network without authentication, any site using the affected versions is accessible to external threats, regardless of whether the site is internal or public.

What should I do if I use Goza?

Immediately audit your environment to identify every instance where the Goza theme is active. Once identified, evaluate the criticality of those specific websites. Coordinate with your application owners to prioritize these instances for remediation planning and ensure that any necessary updates or security configurations are applied to prevent unauthorized file access.

References