First published: Tue Apr 15 2025(Updated: )
Cross-Site Request Forgery (CSRF) vulnerability in LOOS,Inc. Arkhe allows PHP Local File Inclusion. This issue affects Arkhe: from n/a through 3.11.0.
Credit: audit@patchstack.com
Affected Software | Affected Version | How to fix |
---|---|---|
LOOS Arkhe | <=3.11.0 | |
WordPress Arkhe theme | <=3.11.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26748 is considered a high severity vulnerability due to its potential for Cross-Site Request Forgery leading to Local File Inclusion.
To fix CVE-2025-26748, update LOOS Arkhe and the WordPress Arkhe theme to a version beyond 3.11.0.
CVE-2025-26748 could allow attackers to execute unauthorized commands and access sensitive files on affected systems.
CVE-2025-26748 affects LOOS Arkhe versions up to and including 3.11.0 and the corresponding WordPress Arkhe theme.
Yes, CVE-2025-26748 can be exploited remotely, making it particularly dangerous if not promptly addressed.