PT-2026-1496 · Elated Themes · Frappé

Published

2026-01-06

·

Updated

2026-01-06

·

CVE-2025-69083

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Elated-Themes Frappé versions through 1.8
Description An improper control of filename for include/require statement exists in Elated-Themes Frappé, allowing for PHP Local File Inclusion. The issue involves the potential for an attacker to include arbitrary files on the system.
Recommendations Versions prior to 1.8 should be updated.

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-69083

Affected Products

Frappé