CVE-2025-49363
Published: 18 December 2025
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Kings & Queens kings-queens allows PHP Local File Inclusion.This issue affects Kings & Queens: from n/a through <= 1.1.16.
Mitigating Controls (NIST 800-53 r5)AI
Directly addresses improper control of filenames in PHP include/require by enforcing validation of user inputs to prevent path traversal and local file inclusion exploitation.
Requires timely patching or replacement of the vulnerable Kings & Queens WordPress theme (versions <=1.1.16) to remediate the specific PHP LFI flaw.
Boundary protection mechanisms like web application firewalls monitor and block network requests containing malicious file paths targeting the LFI vulnerability.
Security SummaryAI
CVE-2025-49363 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, classified as PHP Remote File Inclusion but enabling PHP Local File Inclusion, in the AncoraThemes Kings & Queens WordPress theme (kings-queens). This issue affects all versions from n/a through 1.1.16 and is associated with CWE-98. The vulnerability was published on 2025-12-18 with a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
The vulnerability can be exploited by unauthenticated attackers (PR:N) over the network (AV:N) without requiring user interaction (UI:N), though it demands high attack complexity (AC:H). Successful exploitation allows attackers to achieve high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H), potentially enabling local file inclusion to access or manipulate sensitive server files.
Mitigation details are available in advisories such as the Patchstack database entry: https://patchstack.com/database/Wordpress/Theme/kings-queens/vulnerability/wordpress-kings-queens-theme-1-1-16-local-file-inclusion-vulnerability?_s_id=cve.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Public-facing WordPress theme vulnerability exploitable remotely without authentication (T1190). Enables local file inclusion for accessing sensitive local files (T1005).