CVE-2026-22478
Published: 05 March 2026
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Elated-Themes FindAll findall allows PHP Local File Inclusion.This issue affects FindAll: from n/a through <= 1.4.
Mitigating Controls (NIST 800-53 r5)AI
Directly mitigates CVE-2026-22478 by requiring timely remediation of the known PHP Local File Inclusion flaw in vulnerable FindAll WordPress theme versions through patching or upgrades.
Enforces validation and sanitization of user-supplied filenames in PHP include/require statements to block malicious local file inclusion paths exploited in this vulnerability.
Establishes secure baseline PHP and web server configuration settings, such as open_basedir restrictions, to limit file system access and mitigate LFI exploitation attempts.
Security SummaryAI
CVE-2026-22478 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, classified as PHP Remote File Inclusion but enabling PHP Local File Inclusion, in the Elated-Themes FindAll WordPress theme. This issue affects FindAll versions from n/a through 1.4 inclusive. It is associated with CWE-98 and received a CVSS 3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating high severity due to network accessibility despite high attack complexity.
An unauthenticated remote attacker can exploit this vulnerability over the network without user interaction. Successful exploitation allows high-impact compromise of confidentiality, integrity, and availability, potentially enabling local file inclusion to access or manipulate sensitive server files.
The Patchstack advisory provides details on this WordPress FindAll theme vulnerability, including mitigation guidance, at https://patchstack.com/database/Wordpress/Theme/findall/vulnerability/wordpress-findall-theme-1-4-local-file-inclusion-vulnerability?_s_id=cve.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
LFI in public-facing WordPress theme enables exploitation of public app (T1190), local file reads for data (T1005), discovery (T1083), and credentials (T1552.001).