Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes LoveDate lovedate allows PHP Local File Inclusion.This issue affects LoveDate: from n/a through < 3.8.6.
Published: 2026-03-25
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion enabling arbitrary file read and potential remote code execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability allows a malicious actor to trigger local file inclusion via an improper filename control in the WordPress LoveDate theme. This flaw can lead to arbitrary file read and, if the attacker can supply PHP code, remote code execution. The weakness is a classic PHP LFI scenario tied to CWE‑98. The impact is limited to files accessible on the web server, but in environments where user‑controlled files are writable, the risk escalates. The description indicates the problem originates from an include/require statement that does not sanitize the path parameter, permitting inclusion of unintended local files.

Affected Systems

The defect is present in the LoveDate theme supplied by jwsthemes for WordPress, affecting all versions from the earliest release up through 3.8.5. Any WordPress installation deploying this theme without patching to 3.8.6 or later is susceptible. No specific CPE strings were listed, but the issue applies to any WordPress instance running the affected theme.

Risk and Exploitability

The CVSS base score of 8.1 classifies the flaw as high severity, while the EPSS score below 1% indicates currently a low probability of exploitation in the wild. The vulnerability is not in the CISA KEV catalog, suggesting no publicly available exploits are known. Attackers would need to craft a request that manipulates the filename parameter to include a local file; the description implies a typical LFI attack vector via a URL or form input. The risk is therefore moderate to high for organizations that cannot deprecate or patch the theme promptly.

Generated by OpenCVE AI on March 26, 2026 at 20:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest LoveDate theme version 3.8.6 or newer to eliminate the vulnerability.
  • If an immediate upgrade is not possible, disable or remove the LoveDate theme until a patched version is available.
  • Review file permissions on the WordPress installation to ensure that only trusted files are writable and that PHP includes are restricted to expected directories.

Generated by OpenCVE AI on March 26, 2026 at 20:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Mar 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Jwsthemes
Jwsthemes lovedate
Wordpress
Wordpress wordpress
Vendors & Products Jwsthemes
Jwsthemes lovedate
Wordpress
Wordpress wordpress

Wed, 25 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in jwsthemes LoveDate lovedate allows PHP Local File Inclusion.This issue affects LoveDate: from n/a through < 3.8.6.
Title WordPress LoveDate theme < 3.8.6 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Jwsthemes Lovedate
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-24T15:35:34.583Z

Reserved: 2026-02-02T12:53:01.429Z

Link: CVE-2026-25381

cve-icon Vulnrichment

Updated: 2026-03-26T18:25:55.639Z

cve-icon NVD

Status : Deferred

Published: 2026-03-25T17:16:48.537

Modified: 2026-04-24T16:35:20.070

Link: CVE-2026-25381

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-27T09:45:49Z

Weaknesses