Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires emphires allows PHP Local File Inclusion.This issue affects Emphires: from n/a through <= 3.9.
Published: 2026-04-08
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Local File Inclusion
Action: Apply Patch
AI Analysis

Impact

The Emphires theme contains a flaw where user-controlled input is passed to PHP's include or require function without proper validation, allowing inclusion of arbitrary local files. This weakness is identified as CWE‑98. When exploited, an attacker could read sensitive configuration files, view database credentials, or if the included file is PHP code, execute it on the server, thereby compromising data confidentiality and integrity.

Affected Systems

WordPress installations that employ the Creatives_Planet Emphires theme version 3.9 or earlier are affected. All releases from the first documented version up to and including 3.9 contain the flaw.

Risk and Exploitability

No CVSS score is listed, EPSS data is unavailable, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector involves a user‑supplied parameter that determines the file path used in the include/require call. Based on the description, it is inferred that the vulnerability could allow a remote attacker to read local files and potentially execute arbitrary PHP code if the site hosts writable PHP scripts, posing a moderate to high risk for publicly accessible WordPress sites that have not been updated.

Generated by OpenCVE AI on April 8, 2026 at 10:45 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Emphires theme to a version newer than 3.9.

Generated by OpenCVE AI on April 8, 2026 at 10:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 08 Apr 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Creatives Planet
Creatives Planet emphires
Wordpress
Wordpress wordpress
Vendors & Products Creatives Planet
Creatives Planet emphires
Wordpress
Wordpress wordpress

Wed, 08 Apr 2026 08:45:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Creatives_Planet Emphires emphires allows PHP Local File Inclusion.This issue affects Emphires: from n/a through <= 3.9.
Title WordPress Emphires theme <= 3.9 - Local File Inclusion vulnerability
Weaknesses CWE-98
References

Subscriptions

Creatives Planet Emphires
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-08T08:30:40.378Z

Reserved: 2026-04-07T10:58:05.155Z

Link: CVE-2026-39677

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-04-08T09:16:39.360

Modified: 2026-04-08T21:26:13.410

Link: CVE-2026-39677

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-08T19:40:58Z

Weaknesses