CVE-2026-22414: WordPress Marra theme <= 1.2 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Marra marra allows PHP Local File Inclusion.This issue affects Marra: from n/a through <= 1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22414?
CVE-2026-22414 has a medium severity due to its potential to allow local file inclusion in vulnerable versions of the Marra theme.
How do I fix CVE-2026-22414?
To fix CVE-2026-22414, update the Marra theme to a version higher than 1.2 where the vulnerability is patched.
What versions of Marra are affected by CVE-2026-22414?
CVE-2026-22414 affects all versions of the Marra theme from its initial release up to version 1.2.
What type of vulnerability is CVE-2026-22414?
CVE-2026-22414 is classified as a Local File Inclusion vulnerability, which can lead to remote code execution.
Who is the vendor responsible for CVE-2026-22414?
The vendor responsible for the Marra theme affected by CVE-2026-22414 is Mikado-Themes.