Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pearson Specter pearsonspecter allows PHP Local File Inclusion.This issue affects Pearson Specter: from n/a through <= 1.11.3.
Published: 2026-01-22
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability stems from an improper control of the filename used in PHP Include/Require statements within the Pearson Specter WordPress theme, classified as CWE‑98. This flaw enables a local file inclusion attack, allowing an attacker to read or execute arbitrary files on the server if they can influence the include path. The impact may range from disclosure of sensitive configuration files to execution of malicious PHP code, potentially leading to full site compromise if the attacker can also inject further attack payloads.

Affected Systems

AncoraThemes Pearson Specter, the WordPress theme, for all released versions up to and including 1.11.3. The issue is stated to affect the theme from the earliest available release (n/a) through 1.11.3.

Risk and Exploitability

The flaw is assigned a CVSS score of 8.1, indicating high severity. The EPSS score is below 1 %, meaning current exploitation activity in the wild is expected to be rare, and the vulnerability is not listed in the CISA KEV catalog. In practice, an attacker would need to supply crafted input parameters or URLs that the theme processes for inclusion; the lack of directory restrictions on include paths makes the local file inclusion vector straightforward once such input is reachable.

Generated by OpenCVE AI on April 29, 2026 at 17:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Pearson Specter theme release once a vendor fix is available; record the new version number in your asset inventory.
  • If no patch is immediately available, disable or delete the Pearson Specter theme from the WordPress installation to eliminate the vulnerable code path.
  • Configure PHP open_basedir or other directory permission restrictions to limit include and require operations to a safe set of directories, reducing the potential impact of a reflectively exploited include path.

Generated by OpenCVE AI on April 29, 2026 at 17:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 29 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 23 Jan 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Thu, 22 Jan 2026 23:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pearson Specter pearsonspecter allows PHP Local File Inclusion.This issue affects Pearson Specter: from n/a through <= 1.11.3.
Title WordPress Pearson Specter theme <= 1.11.3 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:14:36.009Z

Reserved: 2025-12-29T11:19:12.554Z

Link: CVE-2025-69074

cve-icon Vulnrichment

Updated: 2026-01-28T21:32:11.764Z

cve-icon NVD

Status : Deferred

Published: 2026-01-22T17:16:21.473

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-69074

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-29T17:30:16Z

Weaknesses