CVE-2025-49943

8.1

AncoraThemes · Femme

The AncoraThemes Femme theme is vulnerable to local file inclusion due to improper control of filenames used in include or require statements, allowing potential unauthorized file access.

Executive summary

A critical local file inclusion vulnerability in the AncoraThemes Femme theme may allow unauthenticated attackers to access sensitive files or execute arbitrary code on the server.

Vulnerability

This flaw is classified as a Local File Inclusion (CWE-98) occurring within the theme's PHP codebase. An unauthenticated attacker can manipulate filename parameters to include local files, leading to full compromise of confidentiality, integrity, and availability.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational security, as it allows attackers to read sensitive configuration files or execute arbitrary code. Given the CVSS score of 8.1, this represents a high-severity threat that could lead to complete system takeover, unauthorized data exfiltration, and significant reputational damage.

Remediation

Immediate Action: Review the Patchstack advisory for potential updates and ensure the theme is removed or disabled if a patch is not yet provided by the vendor.

Proactive Monitoring: Monitor server access logs for anomalous requests containing path traversal sequences or attempts to access non-public PHP files.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block directory traversal patterns and unauthorized file inclusion attempts targeting the theme directory.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing the AncoraThemes Femme theme must act immediately to mitigate this risk. Given the potential for total system impact, verify the current version in use and prioritize the removal of the theme if a secure version is unavailable. Security teams should maintain heightened vigilance for suspicious web traffic until the software is updated or replaced.

More AncoraThemes CVEs

Sources

Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.