CVE-2026-27990: WordPress ConFix theme <= 1.013 - Local File Inclusion vulnerability
Published Mar 5, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX ConFix confix allows PHP Local File Inclusion.This issue affects ConFix: from n/a through <= 1.013.
Affected Software
2 affected components
ThemeREX ConFix>=n/a, <=1.013
WordPress ConFix<=1.013
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need?
The CVSS vector indicates that exploitation is network-based and requires neither authentication nor user interaction. Exploiting it has high attack complexity.
2
Which installations should be considered affected?
ConFix versions through 1.013 are affected. The affected-version range has no stated lower bound.
3
What could successful exploitation impact?
The CVSS assessment rates confidentiality, integrity, and availability impact as high. Scope is listed as unchanged.
4
How can I determine whether my site is affected?
Identify the installed ConFix theme version. Treat installations running version 1.013 or an earlier version as affected.