CVE-2026-22410: WordPress Dolcino theme <= 1.6 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Dolcino dolcino allows PHP Local File Inclusion.This issue affects Dolcino: from n/a through <= 1.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22410?
CVE-2026-22410 is classified as a high severity vulnerability due to its potential for local file inclusion, which can lead to unauthorized access and data exposure.
How do I fix CVE-2026-22410?
To fix CVE-2026-22410, update the Dolcino theme to the latest version that addresses the local file inclusion vulnerability.
What versions of Dolcino are affected by CVE-2026-22410?
CVE-2026-22410 affects all versions of the Dolcino theme up to and including version 1.6.
What is local file inclusion in the context of CVE-2026-22410?
Local file inclusion allows an attacker to include files on the server through the application's input, potentially leading to code execution and data exposure.
Are there any known exploits for CVE-2026-22410?
Currently, there are no publicly disclosed exploits for CVE-2026-22410, but its high severity indicates potential for exploitation if left unpatched.