theme

Minimog Vulnerabilities

8 known security issues reported for the Minimog WordPress theme. Most recent disclosed Dec 18, 2025.

1 critical 3 high

Running Minimog on your site? Check whether your installed version is affected.

Scan your site free

MinimogWP [minimog] <= 3.9.6 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6.

Affected:
up to 3.9.6
Fix:
No patched version reported
Disclosed:
Dec 18, 2025

CVE-2025-60069 on NVD →

MinimogWP [minimog] <= 3.9.6 (unfixed)

unknown

[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6.

Affected:
up to 3.9.6
Fix:
No patched version reported
Disclosed:
Dec 16, 2025

CVE-2025-68062 on NVD →

MinimogWP <= 3.9.6 - Authenticated (Contributor+) Local File Inclusion

high

The MinimogWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.6. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...

CVSS:
7.5
Affected:
up to 3.9.6
Fix:
No patched version reported
Disclosed:
Dec 13, 2025

CVE-2025-68062 on NVD →

MinimogWP <= 3.9.6 - Unauthenticated Local File Inclusion

high

The MinimogWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, o...

CVSS:
8.1
Affected:
up to 3.9.6
Fix:
No patched version reported
Disclosed:
Aug 2, 2025

CVE-2025-60069 on NVD →

MinimogWP – The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation

high

The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.9.0. This is due to an insufficient check on quantity values when changing quantities in the cart. This makes it possible for unauthenticated attackers to add ite...

CVSS:
7.5
Affected:
up to 3.9.0
Fixed in:
3.9.1
Disclosed:
Jul 25, 2025

CVE-2025-8198 on NVD →

MinimogWP [minimog] < 3.8.0

unknown

[en] The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.7.0 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the e...

Affected:
up to 3.8.0
Fixed in:
3.8.0
Disclosed:
Mar 19, 2025

CVE-2024-13790 on NVD →

MinimogWP – The High Converting eCommerce WordPress Theme <= 3.7.0 - Unauthenticated Local PHP File Inclusion

critical

The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.7.0 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execut...

CVSS:
9.8
Affected:
up to 3.7.0
Fixed in:
3.8.0
Disclosed:
Mar 18, 2025

CVE-2024-13790 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database