Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through < 2.1.6.
Published: 2025-10-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The issue arises from an improper control of filename for include/require in the PHP code of the Billey theme, allowing a local file inclusion vulnerability. An attacker who can manipulate the include path may read arbitrary files on the server or, in some configurations, execute code, thereby compromising the confidentiality, integrity, and potentially the availability of the WordPress site.

Affected Systems

Any installation of the ThemeMove Billey WordPress theme whose version is less than 2.1.6 is affected. The vulnerability exists in all earlier releases of the theme running on WordPress platforms where the vulnerable code resides.

Risk and Exploitability

With a CVSS score of 8.1 the flaw is considered severe, but its EPSS score is below 1%, indicating a low likelihood of active exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is most likely local, triggered by a crafted URL or theme configuration that exposes the dangerous include call; this inference is drawn from the nature of the flaw.

Generated by OpenCVE AI on April 29, 2026 at 20:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied update to version 2.1.6 or newer, which addresses the insecure file inclusion flaw (CWE‑98) by sanitizing include paths and preventing user‑controlled file access.
  • If an immediate upgrade is not feasible, deactivate or uninstall the Billey theme to eliminate the vulnerable include entry point that allows uncontrolled file inclusion (CWE‑98).
  • As a temporary safeguard, configure the web server and file permissions so that only trusted theme files are readable and writable, and block requests to arbitrary include paths, thereby mitigating the potential impact of CWE‑98 until a patch is applied.

Generated by OpenCVE AI on April 29, 2026 at 20:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 29 Jan 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Thememove
Thememove billey
CPEs cpe:2.3:a:thememove:billey:*:*:*:*:*:wordpress:*:*
Vendors & Products Thememove
Thememove billey

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Thu, 23 Oct 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Oct 2025 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Thu, 23 Oct 2025 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 22 Oct 2025 14:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Billey billey allows PHP Local File Inclusion.This issue affects Billey: from n/a through < 2.1.6.
Title WordPress Billey Theme < 2.1.6 - Local File Inclusion Vulnerability
Weaknesses CWE-98
References

Subscriptions

Thememove Billey
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:20:03.224Z

Reserved: 2025-09-17T18:00:39.586Z

Link: CVE-2025-59558

cve-icon Vulnrichment

Updated: 2025-10-23T16:06:39.206Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-22T15:15:55.127

Modified: 2026-01-29T14:34:27.070

Link: CVE-2025-59558

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T21:00:09Z

Weaknesses