CVE-2025-52816 Details
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in themehunk Zita zita allows PHP Local File Inclusion.This issue affects Zita: from n/a through <= 1.6.5.
A local file inclusion vulnerability has been identified in the Themehunk Zita WordPress theme, affecting versions through 1.6.5. This vulnerability arises from improper control of filenames in include or require statements, allowing PHP remote file inclusion that could be exploited for local file inclusion instead.
Users are advised to update to a version of the Themehunk Zita WordPress theme later than 1.6.5. Patchstack has issued a virtual patch to block attacks targeting this vulnerability until an official fix is available.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 27, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://patchstack.com/database/Wordpress/Theme/zita/vulnerability/wordpress-zita-1-6-5-local-file-inclusion-vulnerability?_s_id=cve | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-98 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| themehunk zita | <= 1.6.5 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 23, 2026 | CVE Modified | [email protected] |
| Apr 1, 2026 | CVE Modified | [email protected] |
| Jan 9, 2026 | Initial Analysis | [email protected] |
| Jun 27, 2025 | New CVE Received | [email protected] |