Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This issue affects Besa: from n/a through <= 2.3.15.
Published: 2025-12-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Besa WordPress theme contains an improper validation of filenames used in PHP include/require statements. This weakness, classified as CWE‑98, allows the execution of local file inclusion attacks that give an attacker read access to arbitrary files on the web server. With such access, sensitive configuration information, database credentials, or other secrets could be revealed, and the attacker could use the information to mount further attacks such as remote code execution or privilege escalation.

Affected Systems

All versions of the Besa theme from its initial release through 2.3.15 are impacted. The CVE identifier lists the entire range up to 2.3.15, and no later releases contain a fix, so any installation employing a version at or below 2.3.15 remains vulnerable. The vendor has not provided an official patch or advisory, so the responsibility falls on administrators to upgrade or otherwise mitigate.

Risk and Exploitability

The CVSS score of 7.5 denotes a high severity vulnerability. However, the EPSS score is below 1 %, indicating that the probability of exploitation in the wild is currently low. The vulnerability is not listed in the CISA KEV catalog, so no widely known exploit exists. It is inferred that the attack vector involves a user‑controlled parameter within the WordPress site that is passed to the include/require logic. If exploited, it could lead to data disclosure and potentially serve as a foothold for more advanced attacks.

Generated by OpenCVE AI on April 30, 2026 at 05:00 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Besa theme to a version higher than 2.3.15 as soon as possible.
  • Modify any dynamic include statements in the theme to reference only trusted directories or hard‑code the file path.
  • Disable the PHP configuration option allow_url_include and review file permissions to restrict direct file access.
  • Run a local file inclusion scan of the WordPress installation to ensure no remaining vulnerable include points exist.

Generated by OpenCVE AI on April 30, 2026 at 05:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Thu, 11 Dec 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 10 Dec 2025 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Tue, 09 Dec 2025 14:30:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in thembay Besa besa allows PHP Local File Inclusion.This issue affects Besa: from n/a through <= 2.3.15.
Title WordPress Besa theme <= 2.3.15 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:20.233Z

Reserved: 2025-12-09T12:21:06.412Z

Link: CVE-2025-67530

cve-icon Vulnrichment

Updated: 2025-12-11T18:58:19.056Z

cve-icon NVD

Status : Deferred

Published: 2025-12-09T16:18:27.693

Modified: 2026-04-27T18:16:41.820

Link: CVE-2025-67530

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T05:15:28Z

Weaknesses