CVE-2025-49362
Published: 18 December 2025
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Gracioza gracioza allows PHP Local File Inclusion.This issue affects Gracioza: from n/a through <= 1.0.15.
Mitigating Controls (NIST 800-53 r5)AI
Directly mitigates CVE-2025-49362 by remediating the flaw through patching or upgrading the vulnerable Gracioza WordPress theme to a fixed version.
Prevents arbitrary local file inclusion by enforcing validation of filenames supplied to PHP include/require statements in the Gracioza theme.
Detects the presence of CVE-2025-49362 in WordPress themes via vulnerability scanning, enabling timely remediation.
Security SummaryAI
CVE-2025-49362 is an Improper Control of Filename for Include/Require Statement vulnerability in PHP programs, described as PHP Remote File Inclusion but enabling PHP Local File Inclusion (CWE-98). It affects the Gracioza WordPress theme developed by AncoraThemes, impacting all versions from n/a through 1.0.15. The issue was published on 2025-12-18 with a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to network accessibility and significant impacts on confidentiality, integrity, and availability.
A remote network-based attacker requires no privileges or user interaction but must overcome high attack complexity to exploit the flaw. Successful exploitation allows inclusion of arbitrary local files via uncontrolled PHP include/require statements, potentially leading to sensitive data disclosure, arbitrary code execution, or full server compromise depending on the included files and server configuration.
The primary advisory from Patchstack (https://patchstack.com/database/Wordpress/Theme/gracioza/vulnerability/wordpress-gracioza-theme-1-0-15-local-file-inclusion-vulnerability?_s_id=cve) details the vulnerability in the Gracioza theme. Practitioners should review this reference for patch availability, workaround guidance, and updated theme versions beyond 1.0.15 to mitigate exposure.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
The LFI vulnerability in the public-facing WordPress theme enables remote exploitation of a public-facing application (T1190) and facilitates retrieval of arbitrary data from the local system (T1005) via uncontrolled file inclusion.