Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Towny towny allows PHP Local File Inclusion.This issue affects Towny: from n/a through <= 1.16.
Published: 2025-12-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from improper validation of filenames used in PHP include or require statements within the Towny WordPress theme. An attacker could supply a crafted path that forces the server to read or execute arbitrary local files, potentially revealing confidential data or executing malicious code. The weakness is classified as CWE-98, indicating an insecure file inclusion flaw.

Affected Systems

The Towny theme by Axiom Themes is affected, specifically all releases up to and including version 1.16. Users running these versions on WordPress sites should identify whether the theme is active and determine the installed version.

Risk and Exploitability

The CVSS score of 8.1 marks this issue as high severity, while the EPSS score of less than 1% suggests a low probability of widespread exploitation at present. It is not listed in the CISA KEV catalog, but the high severity warrants prompt attention. The likely attack vector, though not explicitly described, would involve an attacker tricking a logged‑in or public user into loading a malicious local path through a vulnerable parameter or URL. If successful, this could read system or configuration files or execute PHP code.

Generated by OpenCVE AI on April 29, 2026 at 22:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Towny to a version newer than 1.16 or apply the vendor’s patch that restricts include paths
  • Configure the web server or PHP to disallow the use of include/require functions that accept external input, or bind them to a read‑only directory within the WordPress installation
  • If an update is not immediately possible, disable the Towny theme or remove it from active themes until a fixed version is applied, and enforce strict file permission settings on theme directories to prevent unauthorized file access

Generated by OpenCVE AI on April 29, 2026 at 22:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 23 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Axiomthemes
Axiomthemes towny
CPEs cpe:2.3:a:axiomthemes:towny:*:*:*:*:*:wordpress:*:*
Vendors & Products Axiomthemes
Axiomthemes towny

Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Towny towny allows PHP Local File Inclusion.This issue affects Towny: from n/a through <= 1.16.
Title WordPress Towny theme <= 1.16 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Axiomthemes Towny
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:49.162Z

Reserved: 2025-09-05T10:50:25.873Z

Link: CVE-2025-58889

cve-icon Vulnrichment

Updated: 2025-12-18T18:06:13.478Z

cve-icon NVD

Status : Modified

Published: 2025-12-18T08:15:58.033

Modified: 2026-04-27T19:16:15.763

Link: CVE-2025-58889

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:45:06Z

Weaknesses