Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.4.
Published: 2026-03-25
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper control of filenames used in PHP include/require statements within the TieLabs Jannah theme, allowing an attacker to include arbitrary local files on the server. Exploiting this local file inclusion can expose sensitive data such as configuration files, credentials, and potentially serve as a launchpad for further attacks, including code execution or privilege escalation. This weakness is consistent with CWE‑98: Improper Control of Filename for Include/Require Statement.

Affected Systems

TieLabs Jannah theme for WordPress is affected. All versions from the initial release (n/a) through version 7.6.3, inclusive, contain the flaw. The theme is commonly used on WordPress installations, meaning any site employing these theme versions is at risk; no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, while an EPSS score of less than 1% suggests low likelihood of exploitation in the near term. The CVE is not part of the CISA KEV catalog. Vulnerability exploitation would typically occur via the web interface where the theme is active, by sending crafted requests that trigger the vulnerable include. No authentication requirement is mentioned, implying that unauthenticated or low‑privilege users could potentially succeed, with the ultimate impact depending on file system permissions and web server configuration.

Generated by OpenCVE AI on March 26, 2026 at 17:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Jannah theme to the latest patched release (any version newer than 7.6.3).
  • If an update is not immediately available, review the theme’s PHP code to ensure no direct includes of user‑controlled filenames remain, and remove or neutralize such statements if possible.
  • Restrict file system permissions on the WordPress installation to prevent the web server from reading sensitive files such as configuration files or user uploads.

Generated by OpenCVE AI on March 26, 2026 at 17:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.3. Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.4.
Title WordPress Jannah theme <= 7.6.3 - Local File Inclusion vulnerability WordPress Jannah theme <= 7.6.4 - Local File Inclusion vulnerability

Thu, 26 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Mar 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Tielabs
Tielabs jannah
Wordpress
Wordpress wordpress
Vendors & Products Tielabs
Tielabs jannah
Wordpress
Wordpress wordpress

Wed, 25 Mar 2026 16:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.3.
Title WordPress Jannah theme <= 7.6.3 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Tielabs Jannah
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-23T14:14:09.979Z

Reserved: 2026-02-02T12:53:59.641Z

Link: CVE-2026-25464

cve-icon Vulnrichment

Updated: 2026-03-26T15:19:00.497Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-25T17:16:52.563

Modified: 2026-04-23T15:37:12.637

Link: CVE-2026-25464

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-27T09:31:36Z

Weaknesses