Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bailly bailly allows PHP Local File Inclusion.This issue affects Bailly: from n/a through <= 1.3.4.
Published: 2026-01-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Bailly theme contains an improper control of the filename used in a PHP include/require statement, allowing a malicious actor to request arbitrary local files be read or executed. This weakness can expose sensitive configuration files, user data, or credentials, and if the included file contains PHP code, it could result in remote code execution. The vulnerability maps to CWE‑98, which indicates unchecked file inclusion.

Affected Systems

All installations of the WordPress Bailly theme version 1.3.4 or earlier are affected. This includes any WordPress site that has the Bailly theme active, regardless of other plugins or server configuration. The issue is present from the earliest release up to and including 1.3.4.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1, signifying high severity. Its EPSS score is less than 1%, indicating a very low current likelihood of exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is local file inclusion via a crafted request or administrative action that triggers the vulnerable include. Although no publicly known exploits exist, an attacker who can influence the include path could read arbitrary files or execute malicious PHP code.

Generated by OpenCVE AI on April 29, 2026 at 14:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Bailly theme to a version newer than 1.3.4 to remove the vulnerability
  • If an upgrade is not possible, review the theme’s PHP files for include/require statements that use user-supplied input and remove or sanitize them
  • Restrict filesystem permissions so the web server can only read required theme files, and configure the PHP include path to limit inclusion to safe directories

Generated by OpenCVE AI on April 29, 2026 at 14:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Fri, 23 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Bailly bailly allows PHP Local File Inclusion.This issue affects Bailly: from n/a through <= 1.3.4.
Title WordPress Bailly theme <= 1.3.4 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:35.055Z

Reserved: 2025-12-29T11:18:40.734Z

Link: CVE-2025-69039

cve-icon Vulnrichment

Updated: 2026-01-23T20:26:36.178Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:17.000

Modified: 2026-04-27T20:16:26.473

Link: CVE-2025-69039

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T15:00:13Z

Weaknesses