Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Piqes piqes allows PHP Local File Inclusion.This issue affects Piqes: from n/a through <= 1.0.11.
Published: 2026-01-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper control of filename for include/require in PHP code, classified under CWE‑98. It allows an attacker to include arbitrary files from the local filesystem, which can lead to the disclosure of sensitive data or the execution of malicious code if the included files are interpreted as PHP. The primary impact is that a user with sufficient access to trigger the vulnerable include may compromise the confidentiality, integrity, or availability of the site’s files.

Affected Systems

This flaw affects the AncoraThemes Piqes WordPress theme in all revisions up to and including version 1.0.11. No later releases have been documented in the CVE data, so any installation of Piqes 1.0.11 or older is potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity vulnerability. The EPSS score of less than 1 percent suggests a low probability of exploitation at this time, and the issue is not listed in CISA’s Known Exploited Vulnerabilities catalog. Inferred from the description, the likely attack vector is through a local request that supplies a path to the vulnerable include statement; an attacker usually needs at least authenticated access or the ability to manipulate a parameter that the theme processes. If exploitation succeeds, the attacker may read or execute code on the server.

Generated by OpenCVE AI on April 29, 2026 at 10:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Piqes theme to a version newer than 1.0.11 or remove the theme entirely if no update is available.
  • If the theme cannot be updated immediately, disable the theme by switching to a default WordPress theme or deactivate Piqes plugins that rely on the vulnerable include.
  • Apply web‑application firewall rules or configure PHP to disallow file inclusion from arbitrary paths, and ensure allow_url_fopen is disabled to limit remote file inclusion attempts.

Generated by OpenCVE AI on April 29, 2026 at 10:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 29 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Piqes piqes allows PHP Local File Inclusion.This issue affects Piqes: from n/a through <= 1.0.11.
Title WordPress Piqes theme <= 1.0.11 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T20:39:41.194Z

Reserved: 2025-12-29T11:19:06.668Z

Link: CVE-2025-69073

cve-icon Vulnrichment

Updated: 2026-01-28T21:32:51.987Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:21.353

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-69073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T10:30:08Z

Weaknesses