CVE-2026-22494: WordPress Good Homes theme <= 1.3.13 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Good Homes good-homes allows PHP Local File Inclusion.This issue affects Good Homes: from n/a through <= 1.3.13.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22494?
CVE-2026-22494 has been classified as a high severity vulnerability due to its potential for local file inclusion attacks.
How do I fix CVE-2026-22494?
To fix CVE-2026-22494, update the Good Homes theme to the latest version that addresses this vulnerability.
What are the implications of CVE-2026-22494?
CVE-2026-22494 can lead to unauthorized access to sensitive files on the server, which may compromise the security of the application.
Which versions of the Good Homes theme are affected by CVE-2026-22494?
CVE-2026-22494 affects Good Homes theme versions up to and including 1.3.13.
Who is the vendor responsible for CVE-2026-22494?
The vendor responsible for CVE-2026-22494 is ThemeREX, the developer of the Good Homes WordPress theme.