Local File Inclusion Vulnerability in AxiomThemes IPharm by AxiomThemes
CVE-2025-60047

8.1HIGH

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
18 December 2025

What is CVE-2025-60047?

The IPharm theme developed by AxiomThemes contains a vulnerability that allows for improper control of filename during the PHP Include/Require statement. This security flaw enables attackers to perform local file inclusion, which could lead to unauthorized access to sensitive files on the server. Users running IPharm versions up to and including 1.2.3 are particularly at risk, emphasizing the need for immediate action to secure affected installations.

Affected Version(s)

IPharm 0 <= 1.2.3

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bonds | Patchstack Bug Bounty Program
.