CVE-2025-39458: WordPress Foton theme <= 2.5.2 - Local File Inclusion vulnerability
Published May 19, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Foton foton allows PHP Local File Inclusion.This issue affects Foton: from n/a through <= 2.5.2.
Affected Software
3 affected components
Mikado-Themes Foton>=n/a<2.5.2
WordPress Foton<=2.5.2
Qodeinteractive Foton Wordpress<2.6.1
Remediation
Information
Update the WordPress Foton wordpress theme to the latest available version (at least 2.6.1).
Event History
May 19, 2025
CVE Published
via MITRE·06:47 PM
Data Sourced
via MITRE·06:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 PM
DescriptionWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-39458?
CVE-2025-39458 is classified as a significant vulnerability due to its potential for local file inclusion.
2
How do I fix CVE-2025-39458?
To fix CVE-2025-39458, upgrade the Mikado-Themes Foton to version 2.5.3 or later.
3
What are the affected versions for CVE-2025-39458?
CVE-2025-39458 affects Mikado-Themes Foton versions from n/a up to 2.5.2.
4
Can CVE-2025-39458 lead to remote exploits?
CVE-2025-39458 primarily allows local file inclusion, which could potentially lead to remote exploitation if combined with other vulnerabilities.
5
What kind of software is impacted by CVE-2025-39458?
CVE-2025-39458 impacts the Mikado-Themes Foton theme, commonly used in WordPress installations.