CVE-2026-22504: WordPress ProLingua theme <= 1.1.12 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ProLingua prolingua allows PHP Local File Inclusion.This issue affects ProLingua: from n/a through <= 1.1.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22504?
CVE-2026-22504 is classified as a local file inclusion vulnerability that may lead to unauthorized access to the server's file system.
How do I fix CVE-2026-22504?
To fix CVE-2026-22504, update the ProLingua theme to the latest version beyond 1.1.12 where the vulnerability has been patched.
What types of systems are impacted by CVE-2026-22504?
CVE-2026-22504 specifically affects WordPress sites using the ProLingua theme version 1.1.12 and below.
What is the impact of CVE-2026-22504?
The impact of CVE-2026-22504 includes potential unauthorized file access, which can lead to arbitrary code execution or data exposure.
Is it safe to use ProLingua theme version 1.1.12 after discovering CVE-2026-22504?
No, it is not safe to use ProLingua theme version 1.1.12 as it contains a critical vulnerability that requires immediate updating.