CVE-2025-22708: WordPress Mitech theme <= 2.3.4 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Mitech mitech allows PHP Local File Inclusion.This issue affects Mitech: from n/a through <= 2.3.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-22708?
CVE-2025-22708 is classified as a critical severity vulnerability due to its potential for remote file inclusion.
How do I fix CVE-2025-22708?
To fix CVE-2025-22708, update your ThemeMove Mitech installation to version 2.3.5 or later.
What are the potential impacts of CVE-2025-22708?
CVE-2025-22708 can allow an attacker to execute arbitrary PHP code on the server, which may lead to unauthorized access or data compromise.
Which versions of ThemeMove Mitech are affected by CVE-2025-22708?
CVE-2025-22708 affects ThemeMove Mitech versions up to and including 2.3.4.
Is there a workaround for CVE-2025-22708 if I cannot update immediately?
As a temporary workaround for CVE-2025-22708, restrict file inclusion permissions and disable remote file inclusion in your PHP configuration.