Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Algenix algenix allows PHP Local File Inclusion.This issue affects Algenix: from n/a through <= 1.0.
Published: 2025-12-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper validation of filenames used in PHP include/require statements allows an attacker to trigger a local file inclusion (LFI) flaw within the Algenix WordPress theme. When an input path is accepted without sanitization, arbitrary files on the server can be read or, if the files contain executable code, potentially executed in the context of the web application. The vulnerability falls under CWE-98 and can lead to sensitive file disclosure, configuration leakage, or remote code execution, compromising the confidentiality, integrity, and availability of the affected site.

Affected Systems

Axiomthemes Algenix WordPress theme is affected for all releases from the first available version through version 1.0 inclusive. No newer releases are listed, so any instance running Algenix 1.0 or earlier is vulnerable.

Risk and Exploitability

The issue carries a high CVSS score of 8.1, indicating significant risk. The EPSS score is below 1%, suggesting that, although the technical severity is high, the likelihood of exploitation in the near term is low, and the vulnerability is not currently listed in the CISA KEV catalog. Based on the description, the likely attack vector involves a crafted request that causes the theme to include a file path supplied by the user, which would be feasible from a remote source if the theme is exposed to public input. Successful exploitation would allow a threat actor to read sensitive files or execute code on the server.

Generated by OpenCVE AI on April 30, 2026 at 04:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Algenix theme to a version newer than 1.0 or remove the theme entirely if no patch is available.
  • Apply server‑side controls to limit file inclusions, such as configuring the web server or using .htaccess rules to deny execution of arbitrary paths and to restrict file inclusion to known directories.
  • Sanitize any input that can influence include/require statements so that only whitelisted, absolute paths are used; ensure the theme code validates filenames against a known set of safe values to prevent LFI.

Generated by OpenCVE AI on April 30, 2026 at 04:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 23 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Axiomthemes
Axiomthemes algenix
CPEs cpe:2.3:a:axiomthemes:algenix:*:*:*:*:*:wordpress:*:*
Vendors & Products Axiomthemes
Axiomthemes algenix

Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Algenix algenix allows PHP Local File Inclusion.This issue affects Algenix: from n/a through <= 1.0.
Title WordPress Algenix theme <= 1.0 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Axiomthemes Algenix
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:47.648Z

Reserved: 2025-09-05T10:49:12.187Z

Link: CVE-2025-58803

cve-icon Vulnrichment

Updated: 2025-12-18T18:14:43.270Z

cve-icon NVD

Status : Modified

Published: 2025-12-18T08:15:57.380

Modified: 2026-04-27T19:16:15.110

Link: CVE-2025-58803

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:00:14Z

Weaknesses