What the vulnerability does
01Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Paragon paragon allows PHP Local File Inclusion.This issue affects Paragon: from n/a through <= 1.1.
Explanation of Vulnerability in Simple Terms
02Summary
Paragon versions 1.1 and earlier contain a remote code execution vulnerability accessible over the network without authentication. An attacker can execute arbitrary code on the affected system by exploiting improper input handling. This vulnerability requires specific conditions to trigger but grants full system compromise including data theft, modification, and service disruption.
What an attacker can do
03Attacker Capabilities
Run their own code on the server and steal, modify, or delete site data.
Potential impact on your site
04Site Impact
Complete compromise of the site and server; attacker can access all data, modify content, and disable the site.
Conditions required to exploit
05Prerequisites
Network access to the vulnerable Paragon installation; no authentication required.
Key dates
06Disclosure timeline
December 18, 2025
CVE published
April 28, 2026
Record updated