Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Asia Garden asia-garden allows PHP Local File Inclusion.This issue affects Asia Garden: from n/a through <= 1.3.1.
Published: 2026-03-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Potential Remote Code Execution via Local File Inclusion
Action: Immediate Patch
AI Analysis

Impact

The ThemeREX Asia Garden WordPress theme up to version 1.3.1 contains an Improper Control of Filename for Include/Require Statement vulnerability (CWE‑98). User-controlled input is directly used in a PHP include, allowing an attacker to specify arbitrary local files that will be read and executed by the web server. This can lead to disclosure of sensitive data or execution of malicious code on the host, thereby granting remote code execution capabilities.

Affected Systems

WordPress sites using the ThemeREX Asia Garden theme, any installed release from the initial public release through version 1.3.1. All affected installations run the vulnerable code without the presence of any mitigations provided by the theme.

Risk and Exploitability

The vulnerability has a CVSS score of 8.1 and an EPSS score of less than 1 %, indicating a low overall exploitation probability at present, and it is not listed in the CISA KEV catalog. An attacker can trigger the LFI by manipulating a URL parameter or form input that references the theme’s PHP files, potentially performing path traversal to read or execute arbitrary local files. The vulnerability is exploitable from the web server side and requires the theme to be in use; no authentication is explicitly required by the description but the exact scope is not defined. Given the high severity score, the risk remains high if the vulnerability is present, even though current exploitation likelihood appears low.

Generated by OpenCVE AI on April 15, 2026 at 23:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the ThemeREX Asia Garden theme to version 1.3.2 or later, which removes the vulnerable include logic.
  • If an update cannot be applied immediately, restrict the theme’s file inclusion capabilities by configuring PHP’s open_basedir to exclude the theme’s include directory, or disable the theme entirely until a patch is available.
  • Ensure that all WordPress installations run the latest version of PHP and that the web server is configured to prevent untrusted file inclusion; review any user-supplied file paths for proper validation and sanitization to mitigate similar LFI risks in the future.

Generated by OpenCVE AI on April 15, 2026 at 23:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 06 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Themerex
Themerex asia Garden
Wordpress
Wordpress wordpress
Vendors & Products Themerex
Themerex asia Garden
Wordpress
Wordpress wordpress

Thu, 05 Mar 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 05 Mar 2026 06:15:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Asia Garden asia-garden allows PHP Local File Inclusion.This issue affects Asia Garden: from n/a through <= 1.3.1.
Title WordPress Asia Garden theme <= 1.3.1 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Themerex Asia Garden
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-01T14:15:36.197Z

Reserved: 2026-02-25T12:13:39.590Z

Link: CVE-2026-28063

cve-icon Vulnrichment

Updated: 2026-03-05T19:30:46.371Z

cve-icon NVD

Status : Deferred

Published: 2026-03-05T06:16:40.077

Modified: 2026-04-22T21:27:27.950

Link: CVE-2026-28063

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-15T23:15:17Z

Weaknesses