PHP Remote File Inclusion Vulnerability in Gavias Enzio Responsive Business Theme
CVE-2025-31912

8.1HIGH

What is CVE-2025-31912?

A vulnerability exists in the Gavias Enzio - Responsive Business WordPress Theme due to improper control of filename for include/require statements. This flaw allows for Local File Inclusion, which could enable attackers to execute malicious scripts and potentially gain unauthorized access to sensitive information. The issue impacts versions from n/a through 1.1.8, highlighting the importance of timely updates and security measures for users of this theme.

Affected Version(s)

Enzio - Responsive Business WordPress Theme <= 1.1.8

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)
.
CVE-2025-31912 : PHP Remote File Inclusion Vulnerability in Gavias Enzio Responsive Business Theme