Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean TinySalt tinysalt allows PHP Local File Inclusion.This issue affects TinySalt: from n/a through < 3.10.0.
Published: 2025-06-10
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper control of the filename used in a PHP include or require statement within the TinySalt theme. An attacker can manipulate the input that determines this filename, causing the theme to include arbitrary files located on the server. The flaw primarily allows reading of sensitive local files, such as configuration files or backups, which compromises confidentiality. Based on the description, it is inferred that if the included file contains executable PHP code, there exists a potential for remote code execution, though this is not explicitly stated in the advisory.

Affected Systems

The affected product is the TinySalt theme for WordPress, distributed by LoftOcean. The issue applies to all released versions from an unspecified starting point up to, but not including, version 3.10.0.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity. The EPSS score is less than 1%, implying a very low probability of observed exploitation but not zero. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves a crafted URL or form submission that supplies a malicious path to the theme’s include function, requiring only network access to the WordPress site, with no need for elevated privileges. When exploited, the attacker can read arbitrary local files and, as inferred from the LFI nature of the flaw, could potentially execute injected PHP code, leading to a full compromise of the host.

Generated by OpenCVE AI on May 1, 2026 at 07:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the TinySalt theme to version 3.10.0 or later.
  • If an immediate upgrade is not possible, modify the theme’s include calls to validate or hard‑code the file paths, ensuring only trusted directories are included.
  • Verify that the web server has `allow_url_include` disabled and review the theme’s code for any remaining user‑controlled include inputs.

Generated by OpenCVE AI on May 1, 2026 at 07:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-17665 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean TinySalt allows PHP Local File Inclusion.This issue affects TinySalt: from n/a before 3.10.0.
History

Wed, 29 Apr 2026 10:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean TinySalt allows PHP Local File Inclusion.This issue affects TinySalt: from n/a before 3.10.0. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean TinySalt tinysalt allows PHP Local File Inclusion.This issue affects TinySalt: from n/a through < 3.10.0.
Title WordPress TinySalt < 3.10.0 - Local File Inclusion Vulnerability WordPress TinySalt theme < 3.10.0 - Local File Inclusion vulnerability
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Sat, 12 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00151}

epss

{'score': 0.00165}


Tue, 10 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 10 Jun 2025 13:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in LoftOcean TinySalt allows PHP Local File Inclusion.This issue affects TinySalt: from n/a before 3.10.0.
Title WordPress TinySalt < 3.10.0 - Local File Inclusion Vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-29T09:51:55.324Z

Reserved: 2025-06-04T15:44:57.577Z

Link: CVE-2025-49454

cve-icon Vulnrichment

Updated: 2025-06-10T13:15:50.338Z

cve-icon NVD

Status : Deferred

Published: 2025-06-10T13:15:22.733

Modified: 2026-04-29T10:16:48.687

Link: CVE-2025-49454

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-01T07:45:06Z

Weaknesses