PerfreeBlog v4.0.11 has an arbitrary file read vulnerability in the validThemeFilePath function
CVSS Metrics