CVE-2026-22392: WordPress Cortex theme <= 1.9 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Cortex cortex allows PHP Local File Inclusion.This issue affects Cortex: from n/a through <= 1.5.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Cortex cortex allows PHP Local File Inclusion.This issue affects Cortex: from n/a through <= 1.9.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22392?
CVE-2026-22392 is classified as a high severity vulnerability due to its potential for local file inclusion exploits.
How do I fix CVE-2026-22392?
To fix CVE-2026-22392, update the Mikado-Themes Cortex plugin to version 1.6 or later.
What systems are affected by CVE-2026-22392?
CVE-2026-22392 affects versions of Mikado-Themes Cortex theme up to and including version 1.5.
What impact does CVE-2026-22392 have on my website?
If exploited, CVE-2026-22392 can allow attackers to include arbitrary files, leading to unauthorized access or manipulation of your website.
Is CVE-2026-22392 an urgent vulnerability?
Yes, CVE-2026-22392 requires urgent attention as it poses significant security risks if left unpatched.