Local File Inclusion Vulnerability in Lasa Theme by ThemBay
CVE-2025-49253

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
17 June 2025

What is CVE-2025-49253?

The Lasa theme by ThemBay is vulnerable to a Local File Inclusion issue due to improper control of filename in PHP scripts. This vulnerability allows an attacker to potentially include local files, which could lead to data exposure or further exploitation of the web application.

Affected Version(s)

Lasa <= 1.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phat RiO - BlueRock (Patchstack Alliance)
.