PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-22325 AxiomThemes CVE debrief

CVE-2026-22325 is a HIGH severity vulnerability (CVSS Score: 8.1) in the Promo theme, affecting versions up to and including 1.3.0. This vulnerability allows unauthenticated attackers to include local files, potentially leading to sensitive information disclosure or code execution. The vulnerability was published on June 17, 2026, and last modified on the same day. Users of the Promo theme should take immediate action to mitigate this risk.

Vendor
AxiomThemes
Product
Promo
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-17
Original CVE updated
2026-06-17
Advisory published
2026-06-17
Advisory updated
2026-06-17

Who should care

WordPress administrators and users of the Promo theme, especially those with versions 1.3.0 or earlier, should be aware of this vulnerability and take necessary actions to secure their installations.

Technical summary

The vulnerability is caused by an unauthenticated local file inclusion (LFI) weakness in the Promo theme. This allows attackers to access sensitive files on the server, potentially leading to code execution or information disclosure. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 8.1, indicating a HIGH severity level. The CVSS vector is CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H.

Defensive priority

High

Recommended defensive actions

  • Update the Promo theme to a version beyond 1.3.0 if available.
  • Restrict access to sensitive files and directories.
  • Implement additional security measures such as web application firewalls (WAFs).
  • Regularly monitor for suspicious activity and update software.
  • Consider using security plugins or services for WordPress.
  • Review server configurations for proper file permissions.
  • Isolate sensitive data and limit access.

Evidence notes

The information provided is based on data from official sources, including the CVE.org and NVD. The CVE record and NVD detail pages provide comprehensive information about this vulnerability. Additional details can be found in the Patchstack database.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-22325 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-22325

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-22325 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-22325

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.