CVE-2026-22387: WordPress Aviana theme <= 2.1 - Local File Inclusion vulnerability
Published Mar 5, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Aviana aviana allows PHP Local File Inclusion.This issue affects Aviana: from n/a through <= 2.1.
Affected Software
2 affected components
Mikado-Themes Aviana<=2.1
WordPress Aviana<=2.1
Event History
Mar 5, 2026
CVE Published
via MITRE·05:53 AM
Data Sourced
via MITRE·05:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-22387?
CVE-2026-22387 has been classified as a high severity vulnerability due to the risk of Local File Inclusion in the Aviana theme.
2
How do I fix CVE-2026-22387?
To fix CVE-2026-22387, update the Aviana theme to a version later than 2.1.
3
What software is affected by CVE-2026-22387?
CVE-2026-22387 affects the Mikado-Themes Aviana theme, specifically versions up to and including 2.1.
4
What type of vulnerability is CVE-2026-22387?
CVE-2026-22387 is a Local File Inclusion vulnerability that allows unauthorized access to files on the server.
5
Can CVE-2026-22387 lead to remote code execution?
Yes, CVE-2026-22387 can potentially lead to remote code execution if exploited successfully.