CVE-2026-27079: WordPress Amfissa theme <= 1.1 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Mikado-Themes Amfissa amfissa allows PHP Local File Inclusion.This issue affects Amfissa: from n/a through <= 1.1.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27079?
CVE-2026-27079 has a high severity rating due to its potential for Local File Inclusion, which can lead to unauthorized access to sensitive files.
How do I fix CVE-2026-27079?
To fix CVE-2026-27079, update the Amfissa theme to version 1.1.1 or higher, which addresses the vulnerability.
What is Local File Inclusion in the context of CVE-2026-27079?
In the context of CVE-2026-27079, Local File Inclusion allows an attacker to include files from the server, which can lead to code execution.
Is CVE-2026-27079 only a concern for WordPress users?
Yes, CVE-2026-27079 specifically affects users of the Mikado-Themes Amfissa theme on WordPress.
How can I determine if my WordPress site is vulnerable to CVE-2026-27079?
You can determine if your site is vulnerable to CVE-2026-27079 by checking if you are using the Amfissa theme version 1.1 or lower.