CVE-2026-22324: WordPress Melania theme <= 2.5.0 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Melania allows PHP Local File Inclusion.This issue affects Melania: from n/a through 2.5.0.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Melania melania allows PHP Local File Inclusion.This issue affects Melania: from n/a through <= 2.5.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22324?
CVE-2026-22324 is a critical severity Local File Inclusion vulnerability affecting the ThemeREX Melania theme up to version 2.5.0.
How do I fix CVE-2026-22324?
To fix CVE-2026-22324, upgrade the ThemeREX Melania theme to version 2.5.1 or later to mitigate the vulnerability.
Who is affected by CVE-2026-22324?
CVE-2026-22324 affects users of ThemeREX Melania theme versions up to and including 2.5.0.
What type of vulnerability is CVE-2026-22324?
CVE-2026-22324 is classified as a Local File Inclusion vulnerability in a PHP program.
What are the risks associated with CVE-2026-22324?
Exploitation of CVE-2026-22324 may allow attackers to include and execute malicious files on the affected server.