CVE-2026-25464: WordPress Jannah theme <= 7.6.4 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in TieLabs Jannah jannah allows PHP Local File Inclusion.This issue affects Jannah: from n/a through <= 7.6.4.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25464?
CVE-2026-25464 has a moderate severity rating due to the potential for local file inclusion, which can lead to information disclosure.
How do I fix CVE-2026-25464?
To fix CVE-2026-25464, update the Jannah theme to version 7.6.5 or later.
What systems are affected by CVE-2026-25464?
CVE-2026-25464 affects the Jannah theme by TieLabs, specifically versions up to and including 7.6.4.
What types of attacks can CVE-2026-25464 enable?
CVE-2026-25464 can enable local file inclusion attacks, allowing unauthorized access to system files.
Is CVE-2026-25464 related to remote file inclusion vulnerabilities?
Yes, while CVE-2026-25464 is a local file inclusion vulnerability, it is linked to PHP remote file inclusion concepts.