Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove SmilePure smilepure allows PHP Local File Inclusion.This issue affects SmilePure: from n/a through < 1.8.5.
Published: 2025-10-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper control of the filename supplied to PHP's include/require statement allows an attacker to read arbitrary local files and potentially execute code if the included file is interpreted as PHP. The flaw is classified as CWE‑98 (Improper Control of Filename). The impact is a high‑severity security issue that could expose sensitive configuration data, user content, or other secrets stored on the server, and could lead to further compromise of the web application.

Affected Systems

The vulnerability exists in ThemeMove's SmilePure WordPress theme for all versions before 1.8.5, including the initial release. Any WordPress installation deploying the SmilePure theme and running a version older than 1.8.5 is potentially affected.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity with potential for widespread damage if exploited. The EPSS score of less than 1% suggests a low probability of exploitation in the near term, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector involves using the theme’s file inclusion mechanism through a crafted request from an unauthenticated user, though the exact input path is not detailed in the available information and is inferred from the description of a local file inclusion flaw.

Generated by OpenCVE AI on April 29, 2026 at 23:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the SmilePure theme to version 1.8.5 or later to remove the vulnerable file inclusion logic.
  • If an upgrade cannot be applied immediately, temporarily disable the SmilePure theme by switching to another active theme via the WordPress admin interface or via wp‑cli.
  • Restrict the web server’s ability to read sensitive files by enabling PHP’s open_basedir directive to limit file inclusion only to safe directories, and set display_errors to Off to prevent information leakage.

Generated by OpenCVE AI on April 29, 2026 at 23:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 29 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Thememove
Thememove smilepure
CPEs cpe:2.3:a:thememove:smilepure:*:*:*:*:*:wordpress:*:*
Vendors & Products Thememove
Thememove smilepure

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Thu, 23 Oct 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove SmilePure smilepure allows PHP Local File Inclusion.This issue affects SmilePure: from n/a through < 1.8.5.
Title WordPress SmilePure Theme < 1.8.5 - Local File Inclusion Vulnerability
Weaknesses CWE-98
References

Subscriptions

Thememove Smilepure
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:50.561Z

Reserved: 2025-09-06T04:45:02.778Z

Link: CVE-2025-58958

cve-icon Vulnrichment

Updated: 2025-10-23T13:45:03.287Z

cve-icon NVD

Status : Modified

Published: 2025-10-22T15:15:52.413

Modified: 2026-04-27T20:16:22.563

Link: CVE-2025-58958

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T23:45:16Z

Weaknesses