Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Hygia hygia allows PHP Local File Inclusion.This issue affects Hygia: from n/a through <= 1.16.
Published: 2025-12-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is due to an improper control of filename in PHP’s include/require logic, allowing a local file inclusion attack. An attacker can cause the application to open and read files on the server, or potentially execute arbitrary code if the attacker can craft input to include a PHP file. The flaw could expose sensitive configuration files, credentials, or other private data, and may enable further exploitation such as remote code execution when combined with other weaknesses.

Affected Systems

The WordPress Hygia theme by Axiom Themes version 1.16 and earlier is affected. Any installation of this theme that has not been upgraded beyond 1.16 is vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score of <1% suggests a low to very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, but the potential impact remains significant. The precise attack vector is not explicitly detailed in the available information; however, the flaw involves the theme’s file inclusion logic, implying that an attacker could trigger it through crafted request parameters or configuration settings that control the include path. Security teams should consider that, once an attacker gains the ability to influence the include path, they may read sensitive files or inject malicious scripts. The limited exploit probability does not diminish the need for timely remediation.

Generated by OpenCVE AI on April 30, 2026 at 04:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Hygia theme to version 1.17 or later to remove the vulnerable include logic.
  • If an upgrade is not feasible, immediately remove or disable the Hygia theme and replace it with a secure alternative.
  • As a temporary measure, restrict the theme’s ability to read arbitrary files by applying stricter file permission settings or a web‑application firewall rule that blocks attempts to resolve relative paths in include/require calls.

Generated by OpenCVE AI on April 30, 2026 at 04:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Mon, 05 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Axiomthemes
Axiomthemes hygia
CPEs cpe:2.3:a:axiomthemes:hygia:*:*:*:*:*:wordpress:*:*
Vendors & Products Axiomthemes
Axiomthemes hygia

Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Hygia hygia allows PHP Local File Inclusion.This issue affects Hygia: from n/a through <= 1.16.
Title WordPress Hygia theme <= 1.16 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Axiomthemes Hygia
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:25.541Z

Reserved: 2025-06-30T10:46:30.784Z

Link: CVE-2025-53453

cve-icon Vulnrichment

Updated: 2025-12-18T18:27:54.736Z

cve-icon NVD

Status : Modified

Published: 2025-12-18T08:15:55.530

Modified: 2026-04-27T18:16:22.250

Link: CVE-2025-53453

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:00:14Z

Weaknesses