Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Crown Art crown-art allows PHP Local File Inclusion.This issue affects Crown Art: from n/a through <= 1.2.11.
Published: 2026-03-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion
Action: Patch Theme
AI Analysis

Impact

A flaw in AncoraThemes Crown Art allows a site visitor to influence the filename that the PHP code later includes or requires. The theme lacks proper validation on the file path, meaning the attacker can specify an arbitrary path to a file that exists on the server. This can enable the attacker to read sensitive files or, if the attacker can place a PHP–code containing file in a writable location, to execute that code on the server. Based on the description, it is inferred that the vulnerability could be leveraged to compromise site confidentiality or even achieve remote code execution if the attacker can provide a writable directory.

Affected Systems

The vulnerability exists in all WordPress installations that have installed the Crown Art theme at version 1.2.11 or earlier. Any site that has not upgraded beyond 1.2.11 remains exposed.

Risk and Exploitability

The CVSS v3 score of 8.1 classifies it as a high‑severity flaw. The EPSS score of < 1% indicates a low likelihood of public exploitation at this time, and the exposure is not listed in the CISA KEV catalog. The likely attack vector is manipulating the filename parameter used by the theme’s include/require call; exploitation requires the attacker to have write access to, or the ability to point to, a file within the theme directory, or to read a sensitive file from that location. When the attacker controls a writable location or can read a critical file, they may read secrets or escape to inject and run PHP code.

Generated by OpenCVE AI on April 18, 2026 at 09:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Crown Art theme to version 1.2.12 or later, which removes the vulnerable include logic.
  • Restrict write permissions on the Crown Art theme directory so that only the web server process has write access, thereby preventing an attacker from placing malicious files there.
  • Configure the PHP open_basedir directive to limit the directories that the web application can access to only the WordPress root and necessary system directories, reducing the risk of file inclusion.

Generated by OpenCVE AI on April 18, 2026 at 09:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 09 Mar 2026 17:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Ancorathemes
Ancorathemes crown Art
Wordpress
Wordpress wordpress
Vendors & Products Ancorathemes
Ancorathemes crown Art
Wordpress
Wordpress wordpress

Thu, 05 Mar 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Crown Art crown-art allows PHP Local File Inclusion.This issue affects Crown Art: from n/a through <= 1.2.11.
Title WordPress Crown Art theme <= 1.2.11 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Ancorathemes Crown Art
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:13:49.911Z

Reserved: 2026-01-07T12:22:12.276Z

Link: CVE-2026-22434

cve-icon Vulnrichment

Updated: 2026-03-09T16:27:19.121Z

cve-icon NVD

Status : Deferred

Published: 2026-03-05T06:16:17.523

Modified: 2026-04-22T21:26:58.303

Link: CVE-2026-22434

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T10:00:10Z

Weaknesses