CVE-2025-52816: WordPress Zita theme <= 1.6.5 - Local File Inclusion Vulnerability
Published Jun 27, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita zita allows PHP Local File Inclusion.This issue affects Zita: from n/a through <= 1.6.5.
Affected Software
3 affected components
ThemeHunk Zita<=1.6.5
WordPress Zita theme<=1.6.5
ThemeHunk Zita Wordpress<=1.6.5
Event History
Jun 27, 2025
CVE Published
via MITRE·11:52 AM
Data Sourced
via MITRE·11:52 AM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-52816?
CVE-2025-52816 is classified as a high severity vulnerability due to its potential for initiating PHP Local File Inclusion attacks.
2
How do I fix CVE-2025-52816?
To fix CVE-2025-52816, update the ThemeHunk Zita to version 1.6.6 or later to eliminate the vulnerability.
3
What is the impact of CVE-2025-52816 on affected systems?
CVE-2025-52816 allows an attacker to include arbitrary local files, potentially leading to data exposure or code execution.
4
Which versions of Zita are affected by CVE-2025-52816?
CVE-2025-52816 affects all versions of ThemeHunk Zita from its initial release through 1.6.5.
5
Who is the vendor for the software affected by CVE-2025-52816?
The vendor for the affected software is ThemeHunk.