Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themepul TopperPack – Complete Elementor Addons, Theme & CPT Builder topper-pack allows PHP Local File Inclusion.This issue affects TopperPack – Complete Elementor Addons, Theme & CPT Builder: from n/a through <= 1.2.1.
Published: 2026-02-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a classic improper control of filenames used in PHP include/require statements, identified as CWE-98. The plugin’s code allows an attacker to supply a crafted input that causes PHP to read or execute unintended files. This can lead to disclosure of sensitive server files or activation of malicious code, undermining confidentiality, integrity, or availability of the WordPress site and potentially the underlying server. No special privileges are required beyond access to the vulnerable plugin functionality.

Affected Systems

WordPress sites that have installed Themepul’s TopperPack – Complete Elementor Addons, Theme & CPT Builder plugin version 1.2.1 or earlier. The vulnerability applies to all installations of these versions because the issue lies in the plugin’s default filename handling, regardless of individual site configuration.

Risk and Exploitability

The CVSS score of 7.5 reflects a high severity vulnerability. The EPSS score of less than 1% indicates that, while serious, exploitation opportunities are currently scarce. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector is manipulation of URL query parameters or form inputs that specify the filename to include. The attack can be executed remotely without authentication, so public access to the site can provide the necessary entry point.

Generated by OpenCVE AI on April 29, 2026 at 11:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TopperPack to a version newer than 1.2.1 or apply the vendor‑issued patch that sanitizes filename inputs.
  • If updating is not immediately possible, uninstall or disable the TopperPack plugin to eliminate the LFI vector.
  • Configure PHP to restrict include paths to safe directories and enforce strict file permissions to prevent disclosure of sensitive files.

Generated by OpenCVE AI on April 29, 2026 at 11:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Apr 2026 18:30:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themepul TopperPack – Complete Elementor Addons, Theme &amp; CPT Builder topper-pack allows PHP Local File Inclusion.This issue affects TopperPack – Complete Elementor Addons, Theme &amp; CPT Builder: from n/a through <= 1.2.1. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themepul TopperPack – Complete Elementor Addons, Theme & CPT Builder topper-pack allows PHP Local File Inclusion.This issue affects TopperPack – Complete Elementor Addons, Theme & CPT Builder: from n/a through <= 1.2.1.

Tue, 24 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 23 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Themepul
Themepul topperpack – Complete Elementor Addons, Theme &amp; Cpt Builder
Wordpress
Wordpress wordpress
Vendors & Products Themepul
Themepul topperpack – Complete Elementor Addons, Theme &amp; Cpt Builder
Wordpress
Wordpress wordpress

Fri, 20 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Themepul TopperPack – Complete Elementor Addons, Theme &amp; CPT Builder topper-pack allows PHP Local File Inclusion.This issue affects TopperPack – Complete Elementor Addons, Theme &amp; CPT Builder: from n/a through <= 1.2.1.
Title WordPress TopperPack – Complete Elementor Addons, theme & CPT Builder plugin <= 1.2.1 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Themepul Topperpack – Complete Elementor Addons, Theme &amp; Cpt Builder
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:02:40.704Z

Reserved: 2025-12-24T13:59:58.566Z

Link: CVE-2025-68841

cve-icon Vulnrichment

Updated: 2026-02-24T20:11:19.791Z

cve-icon NVD

Status : Deferred

Published: 2026-02-20T16:22:12.727

Modified: 2026-04-28T19:36:00.667

Link: CVE-2025-68841

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T12:00:11Z

Weaknesses