Local File Inclusion Vulnerability in Jannah Theme by TieLabs
CVE-2025-53334

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
28 August 2025

What is CVE-2025-53334?

The Jannah theme by TieLabs is affected by a vulnerability that permits Local File Inclusion (LFI) due to improper handling of filename inputs in PHP. This flaw allows attackers to exploit the functionality and potentially include arbitrary local files on the server. Users running versions n/a through 7.4.1 of the Jannah theme are recommended to apply patches or updates immediately to mitigate risks associated with this vulnerability, enhancing the overall security of their WordPress installations.

Affected Version(s)

Jannah <= 7.4.1

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ananda Dhakal (Patchstack)
.
CVE-2025-53334 : Local File Inclusion Vulnerability in Jannah Theme by TieLabs