CVE-2026-28007: WordPress Coinpress theme <= 1.0.14 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Coinpress coinpress allows PHP Local File Inclusion.This issue affects Coinpress: from n/a through <= 1.0.14.
Affected Software
Event History
Frequently Asked Questions
Which installations are affected?
Coinpress installations running versions through 1.0.14 are affected. The available data does not identify a fixed version or indicate whether any particular WordPress configuration avoids exposure.
What level of attacker access is required?
The CVSS vector indicates that exploitation can be attempted remotely without privileges or user interaction. However, the high attack complexity indicates exploitation requires conditions not described in the available data.
What is the potential impact if exploitation succeeds?
The CVSS assessment rates confidentiality, integrity, and availability impacts as high. This means successful exploitation could have severe consequences for affected sites and their underlying environments.