CVE-2025-15637: WordPress Shuffle theme <= 1.8 - Local File Inclusion vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.
Affected Software
1 affected component
WordPress Shuffle theme<=1.8
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress Shuffle Themeto a version that resolves this vulnerability.Fixed in 1.9
Event History
Aug 20, 2026
CVE Published
via MITRE·12:06 PM
Data Sourced
via MITRE·12:06 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation is network-accessible, though the attack complexity is rated high.
2
Which installations are affected?
WordPress sites using the Shuffle theme version 1.8 or earlier are affected according to the provided data. No configuration prerequisites or exclusions are specified.
3
What is the potential impact?
Successful exploitation can affect confidentiality, integrity, and availability, each rated High. The vulnerability is classified as local file inclusion.