CVE-2026-25457 | Select-Themes Mixtape Plugin up to 2.1 on WordPress filename control
A vulnerability marked as critical has been reported in Select-Themes Mixtape Plugin up to 2.1 on WordPress. The affected element is an unknown function. The manipulation leads to improper control of filename for include/require statement in php program ('php remote file inclusion').
This vulnerability is referenced as CVE-2026-25457. Remote exploitation of the attack is possible. No exploit is available.