CVE-2026-22389: WordPress Cocco theme <= 2.0 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Cocco cocco allows PHP Local File Inclusion.This issue affects Cocco: from n/a through <= 1.5.1.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Cocco cocco allows PHP Local File Inclusion.This issue affects Cocco: from n/a through <= 2.0.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22389?
CVE-2026-22389 is rated as a high-severity vulnerability due to the potential exploitation of local file inclusion leading to unauthorized access to sensitive files.
How do I fix CVE-2026-22389?
To fix CVE-2026-22389, update your Mikado-Themes Cocco theme to version 1.5.2 or later.
What versions of Cocco are affected by CVE-2026-22389?
CVE-2026-22389 affects all versions of Mikado-Themes Cocco up to and including version 1.5.1.
What type of vulnerability is CVE-2026-22389?
CVE-2026-22389 is classified as a Local File Inclusion (LFI) vulnerability.
Who is the vendor responsible for CVE-2026-22389?
The vendor responsible for CVE-2026-22389 is Mikado-Themes.