Multiple Themes by axiomthemes, ThemeRex, and AncoraThemes <= 1.18.0 - Unauthenticated Local File Inclusion
highMultiple themes for WordPress by axiomthemes, ThemeRex, and AncoraThemes are vulnerable to Local File Inclusion in various versions. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to...
- CVSS:
- 8.1
- Affected:
- up to 2.1.11
- Fixed in:
- 2.1.12
- Disclosed:
- Jun 9, 2025