Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Inclusion.This issue affects Overworld: from n/a through <= 1.3.
Published: 2026-01-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Edge-Themes Overworld version 1.3, and earlier releases, contain an improper control of the filename in an include/require statement. The flaw allows an attacker to specify arbitrary local file paths that the PHP runtime will include, possibly leading to disclosure or execution of unintended code. These conditions map directly to CWE-98, where an attacker can get the application to process and serve sensitive files or run malicious scripts.

Affected Systems

All installations of the Edge-Themes Overworld theme up to and including version 1.3 are affected. The theme provides its override files in a WordPress installation, and the vulnerability resides in the theme’s PHP files that handle file inclusion. No other versions or themes are known to contain the issue as defined by the CNA.

Risk and Exploitability

The CVSS score of 8.1 classifies this flaw as high severity. The EPSS score of less than 1 percent indicates that while exploit examples are scarce, the possibility exists for a targeted attack. The vulnerability is not currently listed in CISA’s KEV catalog, suggesting no widespread exploit activity has been documented yet. The likely attack vector is not explicitly documented in the CVE data, but based on the flaw description it appears to involve user-controllable input that dictates the filename used in an include/require call—such as request parameters or cookie values that the theme may accept. This inference is made from the nature of the flaw. Successful exploitation could result in arbitrary file reading or execution of code within the WordPress context.

Generated by OpenCVE AI on April 29, 2026 at 11:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Overworld theme beyond version 1.3 if a patched version is available
  • If an upgrade is not immediately possible, remove or neutralize any theme functionality that accepts user input in file paths and replace it with a static whitelist
  • Enforce file permission restrictions on the WordPress upload and theme directories to prevent inclusion of sensitive system files

Generated by OpenCVE AI on April 29, 2026 at 11:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 29 Jan 2026 01:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 27 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Edge-Themes Overworld overworld allows PHP Local File Inclusion.This issue affects Overworld: from n/a through <= 1.3.
Title WordPress Overworld theme <= 1.3 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:36:08.919Z

Reserved: 2025-12-29T11:18:51.165Z

Link: CVE-2025-69050

cve-icon Vulnrichment

Updated: 2026-01-27T15:37:01.328Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:18.473

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-69050

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T11:15:09Z

Weaknesses