PatchSiren

Case Themes CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Case Themes CVE published 2026-04-10

CVE-2025-5804

A PHP Local File Inclusion vulnerability exists in Case Theme User, a WordPress plugin, due to improper control of filename for include/require statements. This issue affects Case Theme User versions from n/a through < 1.0.4. The vulnerability could lead to unauthorized access to local files or code execution. Defenders should verify exposure, apply patches or mitigations, and monitor for suspicious activ [truncated]