PHP Remote File Inclusion Vulnerability in Gavias Enzio Responsive Business Theme
CVE-2025-31912
8.1HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 23 May 2025
What is CVE-2025-31912?
A vulnerability exists in the Gavias Enzio - Responsive Business WordPress Theme due to improper control of filename for include/require statements. This flaw allows for Local File Inclusion, which could enable attackers to execute malicious scripts and potentially gain unauthorized access to sensitive information. The issue impacts versions from n/a through 1.1.8, highlighting the importance of timely updates and security measures for users of this theme.
Affected Version(s)
Enzio - Responsive Business WordPress Theme <= 1.1.8
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) (Patchstack Alliance)