CVE-2026-22381: WordPress PawFriends - Pet Shop and Veterinary WordPress Theme theme <= 1.3 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes PawFriends - Pet Shop and Veterinary WordPress Theme pawfriends allows PHP Local File Inclusion.This issue affects PawFriends - Pet Shop and Veterinary WordPress Theme: from n/a through <= 1.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22381?
CVE-2026-22381 is classified as a high severity Local File Inclusion vulnerability affecting the PawFriends theme.
How do I fix CVE-2026-22381?
To fix CVE-2026-22381, update the PawFriends WordPress theme to a version higher than 1.3.
What type of vulnerability is CVE-2026-22381?
CVE-2026-22381 is a Local File Inclusion (LFI) vulnerability which can lead to remote file inclusion.
Which software is affected by CVE-2026-22381?
CVE-2026-22381 affects versions of the WordPress PawFriends - Pet Shop and Veterinary Theme up to and including version 1.3.
Can CVE-2026-22381 be exploited remotely?
Yes, CVE-2026-22381 can potentially be exploited remotely, allowing attackers to include arbitrary files.