CVE-2025-26748

WordPress Arkhe theme <= 3.11.0 - CSRF to Local File Inclusion vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in LOOS,Inc. Arkhe allows PHP Local File Inclusion. This issue affects Arkhe: from n/a through 3.11.0.


We have discovered 674 live websites that are affected by CVE-2025-26748.

Run a Free Instant Scan




Affected Software

Product  Arkhe
Category Wordpress Themes
Vulnerable Domains674 live websites (100% of Arkhe install base)
Vulnerable Versions
  • from 0 through 3.11
Vulnerable Versions Count0 versions ( less than 0.1% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Apr 15, 2025
  • Updated - Apr 16, 2025

Credits

  • Dimas Maulana (Patchstack Alliance) (finder)

Website Distribution by Country

Number of websites using CVE-2025-26748
United States22 websites



Japan588 websites
Russia3 websites
Canada2 websites
Cyprus1 websites
Czech Republic1 websites
Germany1 websites
France1 websites
GB1 websites

Website Distribution by TLD

Number of websites using CVE-2025-26748
.com321 websites
.jp148 websites
.co.jp77 websites
.net52 websites
.org21 websites
.info11 websites
.ru2 websites
.be1 websites
.ca1 websites
.co.uk1 websites

Websites affected by CVE-2025-26748

Top websites that are affected by CVE-2025-26748. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com Japan***,***
**********.com Japan***,***
****************.com United States***,***
**********.**.jp Japan***,***
************.com ***,***
****.**.jp Japan***,***
********.**.jp Japan*,***,***
**************.*******.**.jp Japan*,***,***
*************.jp Japan*,***,***
**********.org Japan*,***,***
See full domain list

FAQ

CVE-2025-26748 is Cross-Site Request Forgery (CSRF) in Arkhe
A total of 674 websites have been identified as vulnerable to CVE-2025-26748, based on global website indexing conducted by WebTechSurvey.
The Arkhe is affected by the CVE-2025-26748 vulnerability.
Arkhe versions up to and including 3.11 are vulnerable to CVE-2025-26748.