CVE-2026-28034
Published: 05 March 2026
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Progress progress allows PHP Local File Inclusion.This issue affects Progress: from n/a through <= 1.2.
Mitigating Controls (NIST 800-53 r5)AI
SI-10 mandates validation of user-supplied inputs used in PHP include/require statements, directly preventing improper filename control exploited in this LFI vulnerability.
SI-2 requires timely identification, reporting, and correction of flaws like CVE-2026-28034 in the ThemeREX Progress WordPress theme.
CM-6 establishes and documents secure configuration settings for PHP, such as open_basedir restrictions, to limit the scope of local file access in LFI exploits.
Security SummaryAI
CVE-2026-28034 is an Improper Control of Filename for Include/Require Statement vulnerability, classified as a PHP Local File Inclusion (LFI) issue under CWE-98, affecting the ThemeREX Progress WordPress theme. The vulnerability impacts all versions from n/a through 1.2 inclusive and was published on 2026-03-05.
The vulnerability has a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating network accessibility with no privileges or user interaction required, though high attack complexity is needed. Attackers can exploit it remotely to achieve high impacts on confidentiality, integrity, and availability, potentially allowing inclusion of arbitrary local files via PHP include/require statements.
The Patchstack advisory at https://patchstack.com/database/Wordpress/Theme/progress/vulnerability/wordpress-progress-theme-1-2-local-file-inclusion-vulnerability?_s_id=cve details this Local File Inclusion vulnerability in Progress theme version 1.2 and provides guidance for practitioners on associated patches and mitigations.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
LFI in public-facing WordPress theme allows unauthenticated exploitation (T1190) to read arbitrary local files (T1005, T1083), including those with credentials (T1552.001).