Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Rashy rashy allows PHP Local File Inclusion.This issue affects Rashy: from n/a through <= 1.1.3.
Published: 2026-01-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Rashy theme for WordPress contains an improper control of filename for include/require statements in PHP, enabling a local file inclusion flaw. An attacker who can influence the include path can cause the server to read arbitrary files or execute local PHP scripts, potentially leading to disclosure of confidential data or server compromise. This vulnerability is classed as CWE‑98 and represents a severe breach of confidentiality and integrity for the affected site.

Affected Systems

WordPress sites that use the Rashy theme from goalthemes, specifically all releases up through version 1.1.3. Versions prior to the first release are not known to be affected, but any instance of the theme before the release of the fix is vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% suggests a very low probability of current exploitation. The vulnerability is not included in CISA’s KEV catalog, implying no known high‑profile exploitation currently. Because the flaw requires manipulation of an include path, the attack vector is most likely local or through a crafted request that can be made by a user or malicious script. In the absence of public exploitation evidence, the overall risk remains high due to the serious potential impact if the flaw is exploited within a browser session or via an authenticated path.

Generated by OpenCVE AI on April 29, 2026 at 17:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Rashy theme to version 1.1.4 or later, which removes the faulty include path handling code.
  • If an upgrade is not immediately possible, sanitize and validate any user‑supplied file paths before including them, and implement a strict whitelist of allowable files.
  • Set the PHP configuration option allow_url_include to Off to prevent remote file inclusion, and consider disabling user file uploads to the theme’s configuration area.

Generated by OpenCVE AI on April 29, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Tue, 27 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in goalthemes Rashy rashy allows PHP Local File Inclusion.This issue affects Rashy: from n/a through <= 1.1.3.
Title WordPress Rashy theme <= 1.1.3 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:35.625Z

Reserved: 2025-12-29T11:18:40.734Z

Link: CVE-2025-69043

cve-icon Vulnrichment

Updated: 2026-01-27T20:43:01.176Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:17.513

Modified: 2026-04-27T20:16:26.850

Link: CVE-2025-69043

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T17:30:16Z

Weaknesses