Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2.
Published: 2025-10-31
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an improper control of filename in a PHP include/require statement that allows local file inclusion. Attackers can supply file names that the plugin does not validate, enabling them to read arbitrary files or execute code on the host. This can lead to disclosure of sensitive data or arbitrary code execution, effectively giving the attacker control over the site.

Affected Systems

The affected product is StylemixThemes Consulting Elementor Widgets. All installations of the plugin from any earlier releases up through version 1.4.2 are vulnerable. Administrators should verify the installed version and whether updates have been applied.

Risk and Exploitability

The CVSS score of 7.5 indicates a high‑severity vulnerability. Although the EPSS score is below 1% and the issue is not listed in CISA’s KEV catalog, it remains a serious threat. Exploitation requires triggering the plugin’s include logic, likely via a specific URL or request parameter. This allows an attacker to read or execute files on the server if file permissions permit. No publicly known exploits exist at the time of this analysis, but the potential impact justifies immediate remediation.

Generated by OpenCVE AI on April 29, 2026 at 20:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Consulting Elementor Widgets to the latest available version that contains the fix.
  • If an update cannot be applied, disable or uninstall the Consulting Elementor Widgets plugin.
  • Ensure WordPress file system permissions restrict non‑privileged users from reading or executing arbitrary files in the wp-content directory.
  • Monitor web server and application logs for anomalous file include attempts and investigate any suspicious activity.

Generated by OpenCVE AI on April 29, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 13 Nov 2025 11:30:00 +0000


Thu, 13 Nov 2025 10:45:00 +0000


Mon, 03 Nov 2025 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Stylemixthemes
Stylemixthemes consulting Elementor Widgets
Wordpress
Wordpress wordpress
Vendors & Products Stylemixthemes
Stylemixthemes consulting Elementor Widgets
Wordpress
Wordpress wordpress

Fri, 31 Oct 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 31 Oct 2025 11:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in StylemixThemes Consulting Elementor Widgets consulting-elementor-widgets allows PHP Local File Inclusion.This issue affects Consulting Elementor Widgets: from n/a through <= 1.4.2.
Title WordPress Consulting Elementor Widgets plugin <= 1.4.2 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Stylemixthemes Consulting Elementor Widgets
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:14.317Z

Reserved: 2025-10-31T11:23:15.208Z

Link: CVE-2025-64360

cve-icon Vulnrichment

Updated: 2025-10-31T17:58:58.170Z

cve-icon NVD

Status : Deferred

Published: 2025-10-31T12:15:36.440

Modified: 2026-04-27T16:16:41.207

Link: CVE-2025-64360

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T20:30:19Z

Weaknesses