Multiple Themes by axiomthemes, ThemeRex, and AncoraThemes <= 1.18.0 - Unauthenticated Local File Inclusion

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
CVE CVE-2025-26592
CVSS High (8.1)
Publicly Published June 9, 2025
Last Updated December 11, 2025
Researcher Bonds, Tran Nguyen Bao Khanh
Description

Multiple themes for WordPress by axiomthemes, ThemeRex, and AncoraThemes are vulnerable to Local File Inclusion in various versions. This makes it possible for unauthenticated attackers to include and execute arbitrary .php files on the server, allowing the execution of any PHP code in those files. This can be used to bypass access controls, obtain sensitive data, or achieve code execution in cases where .php file types can be uploaded and included.

References

87 affected software package

Software Type Theme
Software Slug wise-move (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.15
Patched Version
Software Type Theme
Software Slug mediaflex (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.10.0
Patched Version
  • 1.10.0
Software Type Theme
Software Slug alhambra (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.13
Patched Version
Software Type Theme
Software Slug booklovers (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.22.0
Patched Version
  • 2.22.0
Software Type Theme
Software Slug ann (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.33.0
Patched Version
  • 1.33.0
Software Type Theme
Software Slug oldstory-whisky-bar (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.22.0
Patched Version
  • 2.22.0
Software Type Theme
Software Slug playhockey (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.14
Patched Version
Software Type Theme
Software Slug birdily (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.3
Patched Version
Software Type Theme
Software Slug prorange (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.12.0
Patched Version
  • 2.12.0
Software Type Theme
Software Slug childy (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.11.0
Patched Version
  • 1.11.0
Software Type Theme
Software Slug def (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.8.0
Patched Version
  • 1.8.0
Software Type Theme
Software Slug podium (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.12
Patched Version
Software Type Theme
Software Slug anesta (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.1
Patched Version
Software Type Theme
Software Slug belicia (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.14.0
Patched Version
  • 1.14.0
Software Type Theme
Software Slug chakra (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.19.0
Patched Version
  • 1.19.0
Software Type Theme
Software Slug corredo (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.14
Patched Version
Software Type Theme
Software Slug beyoga (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.8.0
Patched Version
  • 2.8.0
Software Type Theme
Software Slug hogwords (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.6
Patched Version
Software Type Theme
Software Slug clothing69 (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.11
Patched Version
  • 1.2.11.1
Software Type Theme
Software Slug alanzo (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.3
Patched Version
  • 1.2.4
Software Type Theme
Software Slug pathwell (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.16
Patched Version
  • 1.1.17
Software Type Theme
Software Slug hampton (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3.3
Patched Version
Software Type Theme
Software Slug carlax (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.1
Patched Version
Software Type Theme
Software Slug hotlock (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.4.5
Patched Version
  • 1.4.5
Software Type Theme
Software Slug elementra (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.0.7
Patched Version
  • 1.0.8
Software Type Theme
Software Slug softic (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.17.0
Patched Version
  • 1.17.0
Software Type Theme
Software Slug juno (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.27.0
Patched Version
  • 2.27.0
Software Type Theme
Software Slug solio (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.12.0
Patched Version
  • 1.12.0
Software Type Theme
Software Slug heaven11 (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.9
Patched Version
Software Type Theme
Software Slug gravity (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3.0
Patched Version
Software Type Theme
Software Slug agora (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.8.0
Patched Version
  • 1.8.0
Software Type Theme
Software Slug insurance-ancora (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.16.0
Patched Version
  • 2.16.0
Software Type Theme
Software Slug chrimson (view on wordpress.org)
Patched? No
Affected Version
  • <= 2.2
Patched Version
Software Type Theme
Software Slug hello-summer (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.3
Patched Version
Software Type Theme
Software Slug gutentype (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.1.11
Patched Version
  • 2.1.12
Software Type Theme
Software Slug chainpress (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.14
Patched Version
Software Type Theme
Software Slug albertino (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.24.0.0
Patched Version
  • 2.24.0.0
Software Type Theme
Software Slug planet-shakers (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.7
Patched Version
Software Type Theme
Software Slug samadhi (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.13
Patched Version
Software Type Theme
Software Slug callie-britt (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.3
Patched Version
  • 1.2.3.1
Software Type Theme
Software Slug vagabonds (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.3.10
Patched Version
Software Type Theme
Software Slug plastica (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.12.0
Patched Version
  • 1.12.0
Software Type Theme
Software Slug credit-card (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.15
Patched Version
Software Type Theme
Software Slug laundrycity (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.17
Patched Version
  • 1.2.18
Software Type Theme
Software Slug smart-casa (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.11
Patched Version
Software Type Theme
Software Slug tax-help (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.23.0
Patched Version
  • 2.23.0
Software Type Theme
Software Slug chardonnay (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.26.0
Patched Version
  • 1.26.0
Software Type Theme
Software Slug angela (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.4.3
Patched Version
Software Type Theme
Software Slug advice (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.17.0
Patched Version
  • 1.17.0
Software Type Theme
Software Slug anubia (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.14
Patched Version
Software Type Theme
Software Slug abogado (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.18.0
Patched Version
  • 1.18.0
Software Type Theme
Software Slug artesia (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.20.0
Patched Version
  • 1.20.0
Software Type Theme
Software Slug edema (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.2.1
Patched Version
  • 1.2.2.1
Software Type Theme
Software Slug accalia (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.5.3
Patched Version
Software Type Theme
Software Slug healthy-blog (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.8
Patched Version
Software Type Theme
Software Slug custom-made (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.17
Patched Version
Software Type Theme
Software Slug partiso (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.12
Patched Version
Software Type Theme
Software Slug camelia (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.2.14
Patched Version
  • 1.2.14.1
Software Type Theme
Software Slug stratego (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.8.0
Patched Version
  • 1.8.0
Software Type Theme
Software Slug alisha-williams (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.0
Patched Version
  • 1.3.1
Software Type Theme
Software Slug stevenwatkins (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.12.0
Patched Version
  • 2.12.0
Software Type Theme
Software Slug inset (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.21.0
Patched Version
  • 1.21.0
Software Type Theme
Software Slug crework (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.1.11
Patched Version
  • 1.1.12
Software Type Theme
Software Slug wine-house (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.21.0
Patched Version
  • 3.21.0
Software Type Theme
Software Slug happy-rider (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.18.0
Patched Version
  • 2.18.0
Software Type Theme
Software Slug kargo (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.13
Patched Version
Software Type Theme
Software Slug drone-media (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.8.0
Patched Version
  • 2.8.0
Software Type Theme
Software Slug adrena (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.13
Patched Version
Software Type Theme
Software Slug carz (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.6.0
Patched Version
  • 1.6.0
Software Type Theme
Software Slug alpha-color (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.4.11.1
Patched Version
Software Type Theme
Software Slug qwery (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 3.6.0
Patched Version
  • 3.6.0
Software Type Theme
Software Slug wotahub (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.2
Patched Version
Software Type Theme
Software Slug soccerclub (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.5.0
Patched Version
  • 2.5.0
Software Type Theme
Software Slug asclepius (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.25.0
Patched Version
  • 1.25.0
Software Type Theme
Software Slug fortunio (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.12.0
Patched Version
  • 2.12.0
Software Type Theme
Software Slug good-wine (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.10
Patched Version
Software Type Theme
Software Slug lab (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 1.3.0
Patched Version
  • 1.3.0
Software Type Theme
Software Slug nazareth (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.16
Patched Version
Software Type Theme
Software Slug city-hostel (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.2.3
Patched Version
Software Type Theme
Software Slug travesia (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.15
Patched Version
Software Type Theme
Software Slug proguards (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.19.0
Patched Version
  • 2.19.0
Software Type Theme
Software Slug studeon (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.15
Patched Version
Software Type Theme
Software Slug bonko (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.0.14
Patched Version
Software Type Theme
Software Slug tantra (view on wordpress.org)
Patched? Yes
Affected Version
  • <= 2.9.0
Patched Version
  • 2.9.0
Software Type Theme
Software Slug preston (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.9
Patched Version
Software Type Theme
Software Slug translang (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.1.16
Patched Version
Software Type Theme
Software Slug prodent (view on wordpress.org)
Patched? No
Affected Version
  • <= 1.5.9
Patched Version
This record contains material that is subject to copyright

Copyright 2012-2026 Defiant Inc.
License: Defiant hereby grants you a perpetual, worldwide, non-exclusive, no-charge, royalty-free, irrevocable copyright license to reproduce, prepare derivative works of, publicly display, publicly perform, sublicense, and distribute this software vulnerability information. Any copy of the software vulnerability information you make for such purposes is authorized provided that you include a hyperlink to this vulnerability record and reproduce Defiant's copyright designation and this license in any such copy. License Detail.