Remote File Inclusion Vulnerability in Elated Themes Academist Product
CVE-2025-62055

Currently unrated

Key Information:

Vendor

WordPress

Status
Vendor
CVE Published:
6 November 2025

What is CVE-2025-62055?

The Elated Themes Academist product is susceptible to a remote file inclusion vulnerability due to improper control over filename inputs in PHP scripts. This can allow an attacker to execute arbitrary PHP code by supplying a malicious file, leading to unauthorized access and potential system compromise. Users of the Academist theme should ensure they are using versions that include necessary patches to mitigate this security risk.

Affected Version(s)

Academist <= n/a

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program
.
CVE-2025-62055 : Remote File Inclusion Vulnerability in Elated Themes Academist Product