CVE-2026-27065: WordPress BuilderPress plugin <= 2.0.1 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThimPress BuilderPress builderpress allows PHP Local File Inclusion.This issue affects BuilderPress: from n/a through <= 2.0.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27065?
CVE-2026-27065 has a high severity rating due to its potential for local file inclusion vulnerabilities that could lead to sensitive file exposure on a server.
How do I fix CVE-2026-27065?
To mitigate CVE-2026-27065, update the ThimPress BuilderPress plugin to version 2.0.2 or later where the vulnerability has been patched.
What systems are affected by CVE-2026-27065?
CVE-2026-27065 affects BuilderPress versions up to and including 2.0.1 installed on WordPress sites.
Can CVE-2026-27065 lead to remote code execution?
While CVE-2026-27065 primarily involves local file inclusion, it can potentially be exploited to execute arbitrary code under certain configurations.
Is CVE-2026-27065 a common vulnerability in WordPress plugins?
Local file inclusion vulnerabilities like CVE-2026-27065 are not uncommon in WordPress plugins, highlighting the importance of regular updates and security reviews.