Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MaxCube maxcube allows PHP Local File Inclusion.This issue affects MaxCube: from n/a through <= 1.3.1.
Published: 2025-12-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

AncoraThemes MaxCube, a WordPress theme, contains an improper control of the filename used in PHP include/require statements. This flaw permits local file inclusion, allowing an attacker to load arbitrary files from the server. The vulnerability can lead to reading sensitive information or, if exploit conditions permit, executing malicious code. The weakness corresponds to CWE‑98, indicating a failure to validate user‑supplied file names correctly.

Affected Systems

The affected product is the MaxCube theme developed by AncoraThemes. All releases up to and including version 1.3.1 are vulnerable. No version before the theme’s inception is listed, so any instance running 1.3.1 or earlier could be impacted.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity. The EPSS score of less than 1% suggests a low probability of exploitation at present, and the vulnerability is not referenced in CISA’s KEV catalog. The attack vector most likely involves manipulating a path used by the theme’s PHP include logic—such as by tampering with a URL parameter or form input—but the description does not detail the exact trigger, so this inference is based on typical LFI exploitation patterns. Because the flaw allows reading or executing files locally, it poses a significant confidentiality and integrity risk if exploited.

Generated by OpenCVE AI on April 29, 2026 at 22:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify all WordPress installations that use the MaxCube theme version 1.3.1 or earlier.
  • Upgrade the MaxCube theme to a version newer than 1.3.1, or replace it with an alternative theme that has fixed the LFI issue.
  • Restrict file permissions and limit PHP’s include path to prevent unauthorized file access, and consider implementing web application firewall rules that block suspicious include path parameters.

Generated by OpenCVE AI on April 29, 2026 at 22:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes MaxCube maxcube allows PHP Local File Inclusion.This issue affects MaxCube: from n/a through <= 1.3.1.
Title WordPress MaxCube theme <= 1.3.1 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:53.803Z

Reserved: 2025-09-25T15:19:32.566Z

Link: CVE-2025-60053

cve-icon Vulnrichment

Updated: 2025-12-18T15:00:48.208Z

cve-icon NVD

Status : Deferred

Published: 2025-12-18T08:16:04.990

Modified: 2026-04-27T18:16:22.947

Link: CVE-2025-60053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T22:30:21Z

Weaknesses