PT-2026-27954 · WordPress · Select-Themes Moments

Published

2026-03-25

·

Updated

2026-03-29

·

CVE-2026-25458

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Select-Themes Moments versions n/a through 2.2
Description A flaw exists in the handling of file names within the include/require statements of a PHP program, specifically a PHP Local File Inclusion issue in Select-Themes Moments. This allows for the inclusion of local files, potentially leading to unauthorized access or code execution.
Recommendations Versions prior to 2.2 should be updated.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-25458

Affected Products

Select-Themes Moments