Local File Inclusion Vulnerability in Aora by thembay
CVE-2025-49260
8.1HIGH
What is CVE-2025-49260?
The thembay Aora theme has a vulnerability that allows for improper control of the filename during PHP file inclusion. This flaw can lead to local file inclusion, exposing sensitive files and potentially allowing attackers to execute malicious scripts. The vulnerability is present in versions of Aora from n/a through 1.3.9, making it crucial for users to update and secure their installations against potential exploitation.
Affected Version(s)
Aora 0 <= 1.3.9