Junglewise Threat Intelligence

CVE-2025-58897: Axiomthemes Fermentio Local File Inclusion

CVE-2025-58897 · Severity: high · CVSS 8.1 · Published 2026-06-02

Vendors: Axiomthemes.

Executive brief

Axiomthemes Fermentio, a theme for WordPress websites, contains a security flaw that allows unauthorized individuals to access sensitive internal files. An attacker could use this to steal database credentials or other configuration data, potentially leading to a full takeover of the website. There is currently no official patch available from the developer.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Axiomthemes Fermentio theme for WordPress (versions up to 1.5.0) due to improper control of filenames in PHP include/require statements (CWE-98). An unauthenticated remote attacker can exploit this by providing malicious input to vulnerable parameters, forcing the application to include and execute local files. This can lead to the disclosure of sensitive information, such as wp-config.php containing database credentials, or potentially remote code execution if the attacker can upload or influence the content of a local file. As of the advisory date, no official patch has been released, and users are advised to use third-party mitigation rules or switch themes.

Affected products

  • Axiomthemes Fermentio up to 1.5.0

Timeline

  • 2025-07-24: other: Vulnerability reported by researcher
  • 2026-05-26: advisory: Patchstack published advisory
  • 2026-06-02: disclosed: CVE published to NVD

References