CVE-2026-27077: WordPress MultiOffice theme <= 1.2 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes MultiOffice multioffice allows PHP Local File Inclusion.This issue affects MultiOffice: from n/a through <= 1.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27077?
CVE-2026-27077 is classified as a critical vulnerability due to its potential to allow local file inclusion that can lead to unauthorized access to sensitive files.
How do I fix CVE-2026-27077?
To fix CVE-2026-27077, update the Mikado-Themes MultiOffice theme to the latest version that addresses the local file inclusion issue.
What specific versions are affected by CVE-2026-27077?
CVE-2026-27077 affects all versions of Mikado-Themes MultiOffice theme up to and including version 1.2.
Can CVE-2026-27077 be exploited remotely?
Yes, CVE-2026-27077 can be exploited remotely by attackers if the vulnerable theme is installed.
What should I do if I cannot update my Mikado-Themes MultiOffice theme due to compatibility issues?
If you cannot update due to compatibility, consider disabling the theme or applying security patches manually to mitigate the vulnerability.