CVE-2025-58958: WordPress SmilePure Theme < 1.8.5 - Local File Inclusion Vulnerability
Published Oct 22, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove SmilePure smilepure allows PHP Local File Inclusion.This issue affects SmilePure: from n/a through < 1.8.5.
Affected Software
3 affected components
ThemeMove SmilePure<1.8.5
WordPress SmilePure Theme<1.8.5
ThemeMove Smilepure Wordpress<1.8.5
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-58958?
CVE-2025-58958 is considered to be a critical vulnerability due to its potential for PHP Local File Inclusion.
2
How do I fix CVE-2025-58958?
To fix CVE-2025-58958, upgrade ThemeMove SmilePure to version 1.8.5 or later.
3
What versions of ThemeMove SmilePure are affected by CVE-2025-58958?
CVE-2025-58958 affects all versions of ThemeMove SmilePure prior to 1.8.5.
4
Can CVE-2025-58958 be exploited remotely?
Yes, CVE-2025-58958 can be exploited remotely allowing attackers to execute arbitrary code.
5
What is the impact of CVE-2025-58958 on user data?
The impact of CVE-2025-58958 may include unauthorized access to sensitive user data and complete server compromise.