CVE-2026-27075: WordPress Belfort theme <= 1.0 - Local File Inclusion vulnerability
Published Mar 25, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Belfort belfort allows PHP Local File Inclusion.This issue affects Belfort: from n/a through <= 1.0.
Affected Software
1 affected component
Mikado-Themes Belfort (WordPress theme)<=1.0
Event History
Mar 25, 2026
CVE Published
via MITRE·04:14 PM
Data Sourced
via MITRE·04:14 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-27075?
CVE-2026-27075 is classified as a high severity vulnerability due to its potential to allow remote file inclusion.
2
How do I fix CVE-2026-27075?
To fix CVE-2026-27075, update the Mikado-Themes Belfort theme to a version beyond 1.0.
3
What type of vulnerability is CVE-2026-27075?
CVE-2026-27075 is a Local File Inclusion vulnerability affecting the Belfort WordPress theme.
4
Which versions of the Belfort theme are affected by CVE-2026-27075?
CVE-2026-27075 affects all versions of the Belfort theme up to and including version 1.0.
5
Who is the vendor of the affected software for CVE-2026-27075?
The vendor of the affected software for CVE-2026-27075 is Mikado-Themes.