Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.12.
Published: 2025-12-18
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in the WordPress Smart SEO theme allows an attacker to control the filename used by an include or require statement in PHP. Because the filename is not properly validated, the application may include arbitrary files from the local filesystem. An attacker could read sensitive files or, if the attacker can write to a location that will be included, could execute arbitrary PHP code, effectively compromising the website.

Affected Systems

The Smart SEO theme from Axiom Themes is affected for every release up to and including version 2.12. Versions prior to the release of the fix are vulnerable. No other products or vendors are listed in the CNA data.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity exploit. The EPSS score of less than 1% suggests that although exploitation is possible, it is not common. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote web attacker who can supply a crafted request that causes the theme to include an attacker‑controlled file. If the attacker can write to a path that will be included, they may gain remote code execution. The weakness is classified as CWE‑98, improper control of filename used for include/require.

Generated by OpenCVE AI on April 29, 2026 at 15:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest patch to the smartSEO theme from Axiom Themes (version 2.13 or newer).
  • If an upgrade cannot be performed immediately, deactivate the Smart SEO theme or replace it with an alternative, non‑vulnerable SEO solution.
  • When the theme must remain installed, configure PHP to disallow remote file inclusion by disabling allow_url_include and restrict open_basedir to exclude sensitive directories, and ensure that the theme’s files are not writable by non‑admin users.

Generated by OpenCVE AI on April 29, 2026 at 15:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 23 Dec 2025 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Axiomthemes
Axiomthemes smartseo
CPEs cpe:2.3:a:axiomthemes:smartseo:*:*:*:*:*:wordpress:*:*
Vendors & Products Axiomthemes
Axiomthemes smartseo

Fri, 19 Dec 2025 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 18 Dec 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 18 Dec 2025 07:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes smart SEO smartSEO allows PHP Local File Inclusion.This issue affects smart SEO: from n/a through <= 2.12.
Title WordPress smart SEO theme <= 2.12 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Axiomthemes Smartseo
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T18:35:57.123Z

Reserved: 2025-09-25T15:19:39.457Z

Link: CVE-2025-60059

cve-icon Vulnrichment

Updated: 2025-12-18T18:17:02.812Z

cve-icon NVD

Status : Modified

Published: 2025-12-18T08:16:05.767

Modified: 2026-01-20T15:17:23.493

Link: CVE-2025-60059

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T16:00:06Z

Weaknesses