Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur struktur allows PHP Local File Inclusion.This issue affects Struktur: from n/a through <= 2.5.1.
Published: 2026-07-13
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Struktur theme for WordPress contains an improper control of filenames used in PHP include/require statements (CWE‑98). This flaw allows an attacker to supply an arbitrary local file path, leading to sensitive information disclosure or the execution of malicious code if the attacker controls the included content (the local code execution possibility is inferred). The vulnerability is classified as a PHP Local File Inclusion, which directly compromises file confidentiality and integrity, and can ultimately affect system availability if exploited repeatedly.

Affected Systems

The flaw affects the Struktur theme versions distributed by Select‑Themes from the earliest known release up through 2.5.1. Any WordPress installation that has this theme enabled is vulnerable regardless of its WordPress or PHP version. The issue does not evolve with newer WordPress releases unless the theme remains unchanged.

Risk and Exploitability

The EPSS exploitation probability of the vulnerability is 0.0037, indicating a very low likelihood of exploitation, and it is not listed in the CISA KEV catalog. The CVSS score of 7.5 indicates substantial severity. The likely attack vector involves manipulating a query string or a parameter accepted by the theme, but this is inferred from typical LFI patterns and not explicitly stated in the advisory.

Generated by OpenCVE AI on July 31, 2026 at 11:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Struktur theme to a release newer than 2.5.1
  • If an upgrade cannot be performed immediately, deactivate the theme and switch to a non‑vulnerable theme
  • Modify the theme or use a plugin to sanitize parameters before include or require calls

Generated by OpenCVE AI on July 31, 2026 at 11:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 13:45:00 +0000

Type Values Removed Values Added
First Time appeared Select-themes
Select-themes struktur
Wordpress
Wordpress wordpress
Vendors & Products Select-themes
Select-themes struktur
Wordpress
Wordpress wordpress

Mon, 13 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Select-Themes Struktur struktur allows PHP Local File Inclusion.This issue affects Struktur: from n/a through <= 2.5.1.
Title WordPress Struktur theme <= 2.5.1 - Local File Inclusion vulnerability
Weaknesses CWE-98
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Select-themes Struktur
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-13T13:57:58.819Z

Reserved: 2026-06-25T08:05:08.367Z

Link: CVE-2026-57802

cve-icon Vulnrichment

Updated: 2026-07-13T13:57:55.316Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:00:05Z

Weaknesses
  • CWE-98

    Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')