← back
CVE-2026-22432highCWE-98

WordPress Woopy theme <= 1.2 - Local File Inclusion vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
In short

The Woopy WordPress theme up to version 1.2 contains a vulnerability that allows attackers to include and execute local files on the server. This can lead to unauthorized access to sensitive files or remote code execution if exploited.

Technical detail

CWE-98 (improper control of filename for include/require statements) in Woopy <= 1.2 allows local file inclusion (LFI) through inadequately sanitized include/require parameters. An attacker with web access can manipulate file path inputs to include arbitrary local files, potentially leading to information disclosure or code execution depending on file accessibility and context.

Summary generated and translated by AI from the official description.
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Woopy woopy allows PHP Local File Inclusion.This issue affects Woopy: from n/a through <= 1.2.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
AncoraThemes · Woopy