CVE-2025-39494: WordPress Wilmër theme < 3.4.2 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Wilmër wilmer allows PHP Local File Inclusion.This issue affects Wilmër: from n/a through < 3.4.2.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-39494?
CVE-2025-39494 is classified as a high-severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2025-39494?
To fix CVE-2025-39494, update the Mikado-Themes Wilmër to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2025-39494?
CVE-2025-39494 is an Improper Control of Filename for Include/Require Statement vulnerability leading to PHP Local File Inclusion.
Which versions are affected by CVE-2025-39494?
CVE-2025-39494 affects Mikado-Themes Wilmër on all versions up to and including n/a.
Can CVE-2025-39494 lead to remote code execution?
Yes, CVE-2025-39494 can allow attackers to execute arbitrary PHP code on the server if exploited.