PatchSiren

ThemeMove CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH ThemeMove CVE published 2026-07-13

CVE-2026-57790

CVE-2026-57790 is a HIGH severity vulnerability in the Billey theme, affecting PHP Local File Inclusion. The issue is caused by Improper Control of Filename for Include/Require Statement in PHP Program. This vulnerability has a CVSS score of 7.5. The vulnerability affects Billey theme version 2.1.8 or earlier. Users of Billey theme should apply patches or mitigations to prevent potential PHP Local File In [truncated]

HIGH ThemeMove CVE published 2026-06-17

CVE-2026-39590

CVE-2026-39590 is an Unauthenticated Local File Inclusion vulnerability in Atomlab theme versions <= 2.4.5. The CVSS score is 8.1, indicating a HIGH severity level. This vulnerability allows unauthenticated attackers to include local files, potentially leading to code execution or information disclosure. Users of Atomlab theme versions <= 2.4.5 should apply patches or mitigations to prevent potential file [truncated]

HIGH ThemeMove CVE published 2026-01-08

CVE-2025-22708

A PHP Remote File Inclusion vulnerability exists in the Mitech theme for WordPress, versions up to and including 2.3.4. This issue allows for Local File Inclusion, potentially leading to unauthorized access and data breaches. The vulnerability has a CVSS score of 8.1 and is classified as HIGH severity. WordPress administrators and users of the affected theme version should assess their exposure, verify an [truncated]

HIGH ThemeMove CVE published 2026-01-08

CVE-2025-22707

A PHP Local File Inclusion vulnerability exists in the Moody theme, affecting versions up to and including 2.7.3. This issue allows for potential PHP Local File Inclusion attacks, which could lead to various security consequences such as code execution or information disclosure. Defenders should assess exposure, prioritize remediation, and verify the effectiveness of compensating controls. The CVE record [truncated]