CVE-2026-22434
Published: 05 March 2026
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Crown Art crown-art allows PHP Local File Inclusion.This issue affects Crown Art: from n/a through <= 1.2.11.
Mitigating Controls (NIST 800-53 r5)AI
Validates filenames passed to PHP include/require statements in the Crown Art theme to block unauthorized local file paths and prevent LFI exploitation.
Remediates the specific PHP file inclusion flaw in Crown Art theme versions through <=1.2.11 by identifying, patching, or upgrading the vulnerable component.
Enforces secure PHP configuration settings like open_basedir restrictions and disabling allow_url_include to limit file access capabilities exploited by this LFI vulnerability.
Security SummaryAI
CVE-2026-22434 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, classified as PHP Remote File Inclusion but enabling PHP Local File Inclusion (LFI), in the Crown Art WordPress theme developed by AncoraThemes. This issue affects Crown Art versions from n/a through 1.2.11, as documented in the CVE published on 2026-03-05.
The vulnerability can be exploited remotely over the network (AV:N) by unauthenticated attackers (PR:N) with no user interaction required (UI:N), though it demands high attack complexity (AC:H) and results in no scope change (S:U). Successful exploitation yields high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H), earning a CVSS v3.1 base score of 8.1 and mapping to CWE-98.
Patchstack's advisory at https://patchstack.com/database/Wordpress/Theme/crown-art/vulnerability/wordpress-crown-art-theme-1-2-11-local-file-inclusion-vulnerability?_s_id=cve provides details on the LFI vulnerability specific to the Crown Art WordPress theme version 1.2.11.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
T1190 for exploitation of public-facing WordPress theme vulnerability; T1005 for local file inclusion enabling access to sensitive local files.