CVE-2026-28081
Published: 05 March 2026
Description
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Windsor windsor allows PHP Local File Inclusion.This issue affects Windsor: from n/a through <= 2.5.0.
Mitigating Controls (NIST 800-53 r5)AI
Mandates timely identification, reporting, and correction of the PHP Local File Inclusion flaw in the Windsor theme versions through 2.5.0.
Requires validation of user-supplied filenames prior to their use in PHP include/require statements to block arbitrary local file inclusion.
Enforces secure baseline PHP configuration settings like disabling allow_url_include and open_basedir restrictions to limit file inclusion capabilities.
Security SummaryAI
CVE-2026-28081 is an Improper Control of Filename for Include/Require Statement vulnerability in PHP programs, classified as a PHP Remote File Inclusion issue that enables PHP Local File Inclusion (CWE-98). It affects the ThemeREX Windsor WordPress theme, with all versions from n/a through 2.5.0 vulnerable. The vulnerability was published on 2026-03-05 and carries a CVSS v3.1 base score of 8.1 (AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
The vulnerability can be exploited remotely by unauthenticated attackers (PR:N) over the network (AV:N) without requiring user interaction (UI:N), though it demands high attack complexity (AC:H). Successful exploitation allows attackers to achieve high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H), potentially enabling arbitrary local file reads and further compromise depending on server configuration.
Patchstack's advisory at https://patchstack.com/database/Wordpress/Theme/windsor/vulnerability/wordpress-windsor-theme-2-5-0-local-file-inclusion-vulnerability?_s_id=cve documents the Local File Inclusion vulnerability specifically in Windsor theme version 2.5.0 and provides details for mitigation in WordPress environments.
Details
- CWE(s)
MITRE ATT&CK Enterprise TechniquesAI
Why these techniques?
Unauthenticated remote exploitation of a public-facing WordPress theme vulnerability (T1190). LFI directly facilitates arbitrary reads from local system files (T1005).