CVE-2026-22397: WordPress Fleur theme <= 2.2.1 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fleur fleur allows PHP Local File Inclusion.This issue affects Fleur: from n/a through <= 2.0.
Other sources
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Fleur fleur allows PHP Local File Inclusion.This issue affects Fleur: from n/a through <= 2.2.1.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22397?
CVE-2026-22397 is rated as a critical severity vulnerability due to its potential for local file inclusion and PHP code execution.
How do I fix CVE-2026-22397?
To fix CVE-2026-22397, update the Mikado-Themes Fleur theme to version 2.2.2 or later.
What impact does CVE-2026-22397 have on my WordPress site?
CVE-2026-22397 may allow attackers to execute arbitrary PHP code on your server, potentially compromising your entire site.
Which versions of the Fleur theme are affected by CVE-2026-22397?
CVE-2026-22397 affects all versions of the Mikado-Themes Fleur theme from its initial release up to and including version 2.2.1.
Is it safe to use versions of Fleur theme after CVE-2026-22397 has been fixed?
Yes, after updating to version 2.2.2 or later, the vulnerability CVE-2026-22397 should no longer pose a risk.