MinimogWP [minimog] <= 3.9.6 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6.
- Affected:
- up to 3.9.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-60069 on NVD →
MinimogWP [minimog] <= 3.9.6 (unfixed)
unknown
[en] Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove MinimogWP minimog allows PHP Local File Inclusion.This issue affects MinimogWP: from n/a through <= 3.9.6.
- Affected:
- up to 3.9.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 16, 2025
CVE-2025-68062 on NVD →
MinimogWP <= 3.9.6 - Authenticated (Contributor+) Local File Inclusion
high
The MinimogWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.6. This makes it possible for authenticated attackers, with contributor-level access and above, to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This...
- CVSS:
- 7.5
- Affected:
- up to 3.9.6
- Fix:
- No patched version reported
- Disclosed:
- Dec 13, 2025
CVE-2025-68062 on NVD →
MinimogWP <= 3.9.6 - Unauthenticated Local File Inclusion
high
The MinimogWP theme for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.9.6. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, o...
- CVSS:
- 8.1
- Affected:
- up to 3.9.6
- Fix:
- No patched version reported
- Disclosed:
- Aug 2, 2025
CVE-2025-60069 on NVD →
MinimogWP – The High Converting eCommerce WordPress Theme <= 3.9.0 - Unauthenticated Price Manipulation
high
The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to price manipulation in all versions up to, and including, 3.9.0. This is due to an insufficient check on quantity values when changing quantities in the cart. This makes it possible for unauthenticated attackers to add ite...
- CVSS:
- 7.5
- Affected:
- up to 3.9.0
- Fixed in:
- 3.9.1
- Disclosed:
- Jul 25, 2025
CVE-2025-8198 on NVD →
MinimogWP [minimog] < 3.8.0
unknown
[en] The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.7.0 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the e...
- Affected:
- up to 3.8.0
- Fixed in:
- 3.8.0
- Disclosed:
- Mar 19, 2025
CVE-2024-13790 on NVD →
MinimogWP – The High Converting eCommerce WordPress Theme <= 3.7.0 - Unauthenticated Local PHP File Inclusion
critical
The MinimogWP – The High Converting eCommerce WordPress Theme theme for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.7.0 via the 'template' parameter. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the server, allowing the execut...
- CVSS:
- 9.8
- Affected:
- up to 3.7.0
- Fixed in:
- 3.8.0
- Disclosed:
- Mar 18, 2025
CVE-2024-13790 on NVD →
MinimogWP [minimog] < 3.9.1
unknown
- Affected:
- up to 3.9.1
- Fixed in:
- 3.9.1
CVE-2025-8198 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database