CVE-2025-54700: WordPress Makeaholic Theme <= 1.8.4 - Local File Inclusion Vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove Makeaholic makeaholic allows PHP Local File Inclusion.This issue affects Makeaholic: from n/a through <= 1.8.4.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54700?
CVE-2025-54700 is classified as a critical vulnerability due to its potential to allow unauthorized access to sensitive files on the server.
How do I fix CVE-2025-54700?
To fix CVE-2025-54700, upgrade the ThemeMove Makeaholic to version 1.8.5 or later to eliminate the local file inclusion issue.
What software is affected by CVE-2025-54700?
CVE-2025-54700 affects ThemeMove Makeaholic versions from n/a through 1.8.4 and WordPress Makeaholic Theme up to version 1.8.4.
Can CVE-2025-54700 lead to remote code execution?
Yes, if exploited, CVE-2025-54700 could lead to remote code execution by allowing attackers to execute arbitrary PHP code on the server.
How can I check if my version is vulnerable to CVE-2025-54700?
To check if your version is vulnerable to CVE-2025-54700, verify if you are using ThemeMove Makeaholic version 1.8.4 or earlier.