Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ninetheme Anarkali anarkali allows PHP Local File Inclusion.This issue affects Anarkali: from n/a through <= 1.0.9.
Published: 2026-01-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper control of the filename used by the include/require statement in WordPress’s Anarkali theme enables an attacker to influence which local file is loaded by the PHP runtime. This flaw can lead to the disclosure of sensitive data or the execution of arbitrary code if a malicious file is read or executed. The weakness is a classic file inclusion problem, classified as CWE‑98, and jeopardizes the confidentiality, integrity, and availability of the affected system.

Affected Systems

The affects the Ninetheme Anarkali WordPress theme through the 1.0.9 release. Any WordPress installation running this theme, or any prior unpatched version, is susceptible.

Risk and Exploitability

The CVSS score of 8.1 signals a high severity risk. The EPSS score of less than 1% signifies that, as of the last assessment, exploitation is unlikely, and the vulnerability is not catalogued in the CISA KEV database. The likely attack vector is local file inclusion via a flaw in the theme’s filename handling, which could be invoked with a crafted request that directs the include to a sensitive or malicious file. While the precise exploitation path requires further details, the high CVSS indicates that the vulnerability can have serious consequences if leveraged.

Generated by OpenCVE AI on April 30, 2026 at 14:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Anarkali theme to the latest version that addresses the file inclusion flaw.
  • If an update is not available, disable or remove the Anarkali theme and switch to a vetted alternative.
  • Inspect the theme’s PHP files for unsanitized include or require statements and replace them with path‑validated, whitelisted logic; if unable to modify, block inclusion attempts via a web application firewall.

Generated by OpenCVE AI on April 30, 2026 at 14:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Mon, 26 Jan 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Ninetheme Anarkali anarkali allows PHP Local File Inclusion.This issue affects Anarkali: from n/a through <= 1.0.9.
Title WordPress Anarkali theme <= 1.0.9 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:12:42.125Z

Reserved: 2025-05-07T09:38:59.113Z

Link: CVE-2025-47474

cve-icon Vulnrichment

Updated: 2026-01-26T22:01:51.264Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:15:54.497

Modified: 2026-04-27T19:16:13.697

Link: CVE-2025-47474

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T14:15:40Z

Weaknesses