Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm Core stockholm-core allows PHP Local File Inclusion.This issue affects Stockholm Core: from n/a through <= 2.4.6.
Published: 2025-12-16
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in Select‑Themes Stockholm Core allows an attacker to manipulate the file name used in an include or require statement. Because the plugin does not properly validate or sanitize this value, an arbitrary local file can be loaded at runtime. An attacker who can influence the value may trigger the execution of local code, read sensitive files, or otherwise compromise the integrity of the WordPress installation. The weakness is identified as CWE‑98.

Affected Systems

All releases of the Stockholm Core WordPress plugin from early versions through 2.4.6 are affected. The affected vendor is Select‑Themes and the product is the Stockholm Core plugin. The public CVE notes indicate the problem applies to every version up to and including 2.4.6; later versions are not listed as vulnerable.

Risk and Exploitability

The CVSS score of 7.5 classifies the flaw as high severity, while the EPSS score of less than 1% suggests very low exploitation probability at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers would need to provide a crafted input that is used as the filename in an include/require call, which likely requires local or authenticated access to the WordPress instance. As a result, the risk is significant for systems that have the vulnerable plugin installed and are exposed to untrusted input or users that can influence plugin parameters.

Generated by OpenCVE AI on April 27, 2026 at 22:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Stockholm Core plugin to a version newer than 2.4.6, which removes the vulnerability.
  • If an immediate upgrade is not feasible, restrict the filesystem access used by the plugin by configuring safe mode or disabling user input that can influence include/require paths.
  • Deploy a web application firewall or input sanitization routine that validates file names against an allowlist before including them.

Generated by OpenCVE AI on April 27, 2026 at 22:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Tue, 20 Jan 2026 15:30:00 +0000


Tue, 20 Jan 2026 14:45:00 +0000


Tue, 16 Dec 2025 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Select-themes
Select-themes stockholm Core
Wordpress
Wordpress wordpress
Vendors & Products Select-themes
Select-themes stockholm Core
Wordpress
Wordpress wordpress

Tue, 16 Dec 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 16 Dec 2025 08:30:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Stockholm Core stockholm-core allows PHP Local File Inclusion.This issue affects Stockholm Core: from n/a through <= 2.4.6.
Title WordPress Stockholm Core plugin <= 2.4.6 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Select-themes Stockholm Core
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:28.195Z

Reserved: 2025-12-15T10:01:19.544Z

Link: CVE-2025-68067

cve-icon Vulnrichment

Updated: 2025-12-16T15:25:22.666Z

cve-icon NVD

Status : Deferred

Published: 2025-12-16T09:16:02.010

Modified: 2026-04-27T19:16:24.550

Link: CVE-2025-68067

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-27T22:30:14Z

Weaknesses