← back
CVE-2026-22431highCWE-98

WordPress Wabi-Sabi theme <= 1.2 - Local File Inclusion vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
In short

The Wabi-Sabi WordPress theme version 1.2 and earlier has a flaw that allows attackers to include and execute arbitrary local files on the server, potentially exposing sensitive information or compromising the website.

Technical detail

PHP Local File Inclusion (LFI) vulnerability in Wabi-Sabi theme <= 1.2 due to improper input validation on file inclusion parameters. An unauthenticated attacker can manipulate include/require statements to access arbitrary local files on the server filesystem, leading to information disclosure or code execution depending on accessible file contents and permissions.

Summary generated and translated by AI from the official description.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Wabi-Sabi wabi-sabi allows PHP Local File Inclusion.This issue affects Wabi-Sabi: from n/a through <= 1.2.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
AncoraThemes · Wabi-Sabi