HIGH
Case Themes
CVE published 2026-04-10
CVE-2025-5804
A PHP Local File Inclusion vulnerability exists in Case Theme User, a WordPress plugin, due to improper control of filename for include/require statements. This issue affects Case Theme User versions from n/a through < 1.0.4. The vulnerability could lead to unauthorized access to local files or code execution. Defenders should verify exposure, apply patches or mitigations, and monitor for suspicious activ [truncated]