CVE-2026-27047: WordPress Curly Core plugin <= 2.1.6 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Curly Core curly-core allows PHP Local File Inclusion.This issue affects Curly Core: from n/a through <= 2.1.6.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27047?
CVE-2026-27047 is considered a critical local file inclusion vulnerability that may lead to remote code execution.
How do I fix CVE-2026-27047?
To fix CVE-2026-27047, update the Mikado-Themes Curly Core plugin to version 2.1.7 or later.
What versions are affected by CVE-2026-27047?
CVE-2026-27047 affects Mikado-Themes Curly Core plugin versions up to and including 2.1.6.
What are the potential impacts of CVE-2026-27047?
The potential impacts of CVE-2026-27047 include unauthorized access to sensitive files and potential remote code execution.
Is CVE-2026-27047 actively exploited in the wild?
There have been reports indicating that CVE-2026-27047 may be actively exploited, making it crucial to apply updates promptly.