PHP Remote File Inclusion Vulnerability in Axiomthemes Crafti Theme
CVE-2025-58705
8.1HIGH
What is CVE-2025-58705?
A vulnerability in the Axiomthemes Crafti theme allows attackers to exploit improper control over filenames during include or require operations. This flaw potentially enables unauthorized access to sensitive files on the server by allowing local file inclusion. Affected versions of Crafti are from n/a up to 1.12, highlighting the importance for users to review and apply security measures promptly.
Affected Version(s)
Crafti <= 1.12