CVE-2025-59564: WordPress EduMall Theme < 4.4.5 - Local File Inclusion Vulnerability
Published Oct 22, 2025
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeMove EduMall edumall allows PHP Local File Inclusion.This issue affects EduMall: from n/a through < 4.4.5.
Affected Software
3 affected components
ThemeMove EduMall<4.4.5
WordPress EduMall Theme<4.4.5
ThemeMove Edumall Wordpress<4.4.5
Event History
Oct 22, 2025
CVE Published
via MITRE·02:32 PM
Data Sourced
via MITRE·02:32 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59564?
CVE-2025-59564 is classified as a critical vulnerability due to the potential for remote file inclusion.
2
How do I fix CVE-2025-59564?
To fix CVE-2025-59564, you should update the EduMall theme to version 4.4.5 or later.
3
What type of vulnerability is CVE-2025-59564?
CVE-2025-59564 is classified as a PHP Local File Inclusion vulnerability.
4
Which versions of EduMall are affected by CVE-2025-59564?
CVE-2025-59564 affects all versions of EduMall prior to 4.4.5.
5
Is CVE-2025-59564 applicable to WordPress EduMall Theme?
Yes, CVE-2025-59564 is also applicable to the WordPress EduMall theme versions before 4.4.5.