CVE-2025-14429: WordPress AeroLand theme <= 1.6.6 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove AeroLand aeroland allows PHP Local File Inclusion.This issue affects AeroLand: from n/a through <= 1.6.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-14429?
CVE-2025-14429 has been classified with a high severity due to its potential for local file inclusion, which can lead to unauthorized access to sensitive files.
How do I fix CVE-2025-14429?
To mitigate CVE-2025-14429, you should update ThemeMove AeroLand to version 1.6.7 or later.
What does CVE-2025-14429 exploit?
CVE-2025-14429 exploits improper control of filename for include/require statements in PHP, allowing for local file inclusion.
Which versions of ThemeMove AeroLand are affected by CVE-2025-14429?
CVE-2025-14429 affects all versions of ThemeMove AeroLand up to and including 1.6.6.
Is there a workaround for CVE-2025-14429?
A temporary workaround for CVE-2025-14429 is to disable any features that allow user input for file paths or includes.