CVE-2026-22427: WordPress GoTravel theme <= 2.1 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes GoTravel gotravel allows PHP Local File Inclusion.This issue affects GoTravel: from n/a through <= 2.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22427?
CVE-2026-22427 is classified as a critical vulnerability due to the potential for local file inclusion, which can lead to unauthorized access to sensitive files.
How do I fix CVE-2026-22427?
To fix CVE-2026-22427, update the GoTravel theme to version 2.2 or higher, which addresses the local file inclusion vulnerability.
What type of vulnerability is CVE-2026-22427?
CVE-2026-22427 is a local file inclusion vulnerability that allows attackers to manipulate PHP include statements.
Who is affected by CVE-2026-22427?
CVE-2026-22427 affects users of the Mikado-Themes GoTravel theme in versions up to and including 2.1.
Can CVE-2026-22427 lead to remote code execution?
While CVE-2026-22427 primarily allows local file inclusion, it can potentially lead to remote code execution if exploited in conjunction with other vulnerabilities.