HIGH
JanStudio
CVE published 2026-01-07
CVE-2025-69080
A PHP Remote File Inclusion vulnerability exists in JanStudio Gecko theme version 1.9.8 and earlier. This issue allows attackers to include local files via a manipulated filename. Defenders should assess exposure, particularly those managing PHP applications and WordPress themes. The vulnerability's impact on confidentiality, integrity, and availability is rated high with a CVSS score of 8.1.