Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Vicky snsvicky allows PHP Local File Inclusion.This issue affects SNS Vicky: from n/a through <= 3.7.
Published: 2025-06-27
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SNS Vicky WordPress theme exposes an improper control of filename for include/require statements, creating a Local File Inclusion (LFI) flaw. An attacker can provide an arbitrary file path that the theme processes, potentially allowing access to sensitive files or, if a PHP file they control is included, the execution of malicious code. This weakness is categorized as CWE‑98 and has a CVSS score of 8.1, indicating high severity. Based on the description, it is inferred that an attacker might be able to include arbitrary files if the theme accepts user‑controlled input without proper validation.

Affected Systems

The vulnerability affects the SNS Vicky theme distributed by snstheme, impacting all releases from the initial version through version 3.7 inclusive. Users using any of these versions on a WordPress installation must verify whether they are running a version newer than 3.7 or consider removing the theme.

Risk and Exploitability

The EPSS score of less than 1% indicates a low probability of exploitation at this time, though the CVSS score of 8.1 reflects a high potential impact. The theme does not require elevated privileges; an attacker who can influence parameters sent to it—typically through crafted URLs or form submissions—can trigger the LFI. If a PHP file that contains executable code resides on the server and can be referenced by the attacker, execution of that code could follow. The vulnerability is not listed in the CISA KEV catalog, but its high severity and the necessity of a public fix warrant timely remediation.

Generated by OpenCVE AI on May 2, 2026 at 01:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the SNS Vicky theme to a version newer than 3.7 that contains the fix for the LFI issue.
  • If upgrading is not possible, modify the theme’s PHP files to validate or whitelist the filenames used in include/require calls, or comment out the vulnerable function until an official update is applied.
  • If the theme is no longer needed, remove it from the WordPress installation to eliminate the threat surface.

Generated by OpenCVE AI on May 2, 2026 at 01:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-19271 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Vicky allows PHP Local File Inclusion. This issue affects SNS Vicky: from n/a through 3.7.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Vicky allows PHP Local File Inclusion. This issue affects SNS Vicky: from n/a through 3.7. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Vicky snsvicky allows PHP Local File Inclusion.This issue affects SNS Vicky: from n/a through <= 3.7.
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 27 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Jun 2025 12:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in snstheme SNS Vicky allows PHP Local File Inclusion. This issue affects SNS Vicky: from n/a through 3.7.
Title WordPress SNS Vicky theme <= 3.7 - Local File Inclusion Vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:11:52.530Z

Reserved: 2025-03-11T08:10:44.966Z

Link: CVE-2025-28990

cve-icon Vulnrichment

Updated: 2025-06-27T14:05:00.560Z

cve-icon NVD

Status : Deferred

Published: 2025-06-27T12:15:33.033

Modified: 2026-04-23T15:26:44.357

Link: CVE-2025-28990

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-02T01:30:16Z

Weaknesses