CVE-2026-22509
Published: 25 March 2026
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes Gioia gioia allows PHP Local File Inclusion.This issue affects Gioia: from n/a through <= 1.4.
Mitigating Controls (NIST 800-53 r5)AI
Directly remediates the LFI vulnerability in the Gioia WordPress theme by identifying, reporting, and applying patches to affected versions up to 1.4.
Validates user-supplied filenames in PHP include/require statements to block malicious local file paths exploited in this CVE.
Establishes secure PHP configuration settings such as open_basedir restrictions to limit file access and prevent LFI exploitation.
Security SummaryAI
CVE-2026-22509 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, classified as PHP Remote File Inclusion but enabling PHP Local File Inclusion, in the Elated-Themes Gioia WordPress theme. This issue affects Gioia versions from n/a through 1.4, as documented with CWE-98 and published on 2026-03-25.
Unauthenticated attackers can exploit this vulnerability remotely (AV:N), though it requires high attack complexity (AC:H) and no user interaction (UI:N) or privileges (PR:N). Successful exploitation results in high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H), with an overall CVSS 3.1 score of 8.1 and unchanged scope (S:U), potentially allowing local file access through manipulated include/require statements.
The Patchstack advisory at https://patchstack.com/database/Wordpress/Theme/gioia/vulnerability/wordpress-gioia-theme-1-4-local-file-inclusion-vulnerability?_s_id=cve details the Local File Inclusion vulnerability in the WordPress Gioia theme version 1.4.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Unauthenticated remote exploitation of a public-facing WordPress theme vulnerability (T1190) via local file inclusion, enabling collection of data from the local system (T1005) through disclosure of sensitive files and potential code execution.