CVE-2025-54700

8.1

ThemeMove · Makeaholic

A Local File Inclusion vulnerability in the ThemeMove Makeaholic theme allows unauthenticated attackers to include arbitrary files, potentially leading to remote code execution.

Executive summary

The ThemeMove Makeaholic theme is vulnerable to Local File Inclusion, which poses a high risk of unauthorized file access and potential code execution by unauthenticated remote attackers.

Vulnerability

The theme contains an improper control of filenames for include statements, allowing an unauthenticated attacker to perform Local File Inclusion. This flaw enables the inclusion and execution of arbitrary files on the server.

Business impact

Successful exploitation allows an attacker to read sensitive files or execute arbitrary PHP code on the underlying server. Given the CVSS score of 8.1, this vulnerability presents a critical threat to data confidentiality, system integrity, and service availability, potentially leading to a complete compromise of the affected WordPress site.

Remediation

Immediate Action: Since no official patch is currently confirmed, administrators should immediately deactivate or uninstall the Makeaholic theme until the vendor releases a secure version.

Proactive Monitoring: Security teams should audit web server access logs for suspicious patterns, such as directory traversal characters or unexpected file path inclusions, originating from external IP addresses.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common Local File Inclusion payloads and directory traversal attempts directed at the WordPress environment.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The severity of this Local File Inclusion vulnerability necessitates immediate defensive action. Organizations currently utilizing the Makeaholic theme must prioritize its removal or deactivation, as unauthenticated attackers can leverage this flaw to gain full control over the application server. Monitor vendor channels closely for the release of a security patch.

More ThemeMove CVEs

Sources

Originally found and disclosed by Tran Nguyen Bao Khanh (VCI - VNPT Cyber Immunity) | Patchstack Bug Bounty Program, per the CVE Program record.