CVE-2026-28013
Published: 05 March 2026
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Kratz kratz allows PHP Local File Inclusion.This issue affects Kratz: from n/a through <= 1.0.12.
Mitigating Controls (NIST 800-53 r5)AI
Directly mitigates improper filename control in PHP include/require by requiring validation of user-supplied inputs to prevent local file inclusion of arbitrary files.
Requires timely discovery, assessment, and patching of the specific LFI flaw in Kratz WordPress theme versions through 1.0.12.
Enforces secure PHP configuration settings such as open_basedir restrictions to limit filesystem access and block LFI exploitation.
Security SummaryAI
CVE-2026-28013 is an Improper Control of Filename for Include/Require Statement in PHP Program vulnerability, known as PHP Remote File Inclusion, that enables PHP Local File Inclusion in the ThemeREX Kratz WordPress theme. This issue affects Kratz versions from n/a through 1.0.12 and is associated with CWE-98. The vulnerability was published on 2026-03-05 with a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Unauthenticated remote attackers can exploit this vulnerability over the network, though it requires high attack complexity and no user interaction. Successful exploitation allows high-impact compromise of confidentiality, integrity, and availability, potentially enabling local file inclusion to read sensitive files or, in some cases, lead to further code execution depending on the included files.
The Patchstack advisory provides details on this Local File Inclusion vulnerability in the Kratz WordPress theme version 1.0.12, including mitigation guidance, available at https://patchstack.com/database/Wordpress/Theme/kratz/vulnerability/wordpress-kratz-theme-1-0-12-local-file-inclusion-vulnerability?_s_id=cve.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Vulnerability in public-facing WordPress theme enables remote exploitation via local file inclusion (T1190), directly facilitating access to and potential execution of local system files (T1005).