Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme window-ac-services allows PHP Local File Inclusion.This issue affects AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme: from n/a through <= 1.2.5.
Published: 2026-03-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local file inclusion enabling read of arbitrary server files
Action: Immediate patch
AI Analysis

Impact

The vulnerability is a Local File Inclusion flaw that allows an attacker to manipulate a file path used in a PHP include/require statement. If exploited, the attacker could read sensitive files such as configuration files or user passwords, and could potentially use the LFI to facilitate further code execution or data exfiltration. The impact breadth spans from confidentiality loss to possible escalation to full remote code execution, as the flaw can be leveraged to access files server‑side with the privileges of the web process.

Affected Systems

WordPress sites that use the AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme from any version up to and including 1.2.5. Users of this theme should check whether their installation matches the affected range and includes the theme as the primary plugins or template package.

Risk and Exploitability

The CVSS base score of 8.1 designates a high severity vulnerability, while the EPSS of less than 1% indicates a currently low probability of exploitation. The flaw is not listed in CISA’s KEV catalog, suggesting no publicly known active exploitation. Attackers can trigger the flaw by crafting a request that causes the theme to include a file path influenced by user input. Successful exploitation requires that the web server permit the inclusion of local files via PHP, and that the target’s WordPress environment be reachable over the network.

Generated by OpenCVE AI on April 15, 2026 at 23:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the AC Services theme to a version newer than 1.2.5, which removes the vulnerable include call.
  • If an immediate update is not possible, restrict the file path supplied to the include/require function by sanitizing all user‑controlled input and denying traversal characters or absolute paths.
  • Deploy a web application firewall or modify the .htaccess/PHP configuration to block access to sensitive system files (e.g., /etc/passwd, wp-config.php) and to deny directory traversal patterns in requests.

Generated by OpenCVE AI on April 15, 2026 at 23:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 09 Mar 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Axiomthemes
Axiomthemes ac Services | Hvac, Air Conditioning & Heating Company Wordpress Theme
Wordpress
Wordpress wordpress
Vendors & Products Axiomthemes
Axiomthemes ac Services | Hvac, Air Conditioning & Heating Company Wordpress Theme
Wordpress
Wordpress wordpress

Thu, 05 Mar 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme window-ac-services allows PHP Local File Inclusion.This issue affects AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme: from n/a through <= 1.2.5.
Title WordPress AC Services | HVAC, Air Conditioning & Heating Company WordPress Theme theme <= 1.2.5 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Axiomthemes Ac Services | Hvac, Air Conditioning & Heating Company Wordpress Theme
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:15:01.792Z

Reserved: 2026-02-19T09:51:27.897Z

Link: CVE-2026-27326

cve-icon Vulnrichment

Updated: 2026-03-09T16:03:52.164Z

cve-icon NVD

Status : Deferred

Published: 2026-03-05T06:16:23.563

Modified: 2026-04-22T21:26:58.303

Link: CVE-2026-27326

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T23:45:05Z

Weaknesses