CVE-2026-28018: WordPress Global Logistics theme <= 3.20 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Global Logistics globallogistics allows PHP Local File Inclusion.This issue affects Global Logistics: from n/a through <= 3.20.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28018?
CVE-2026-28018 is considered a high severity vulnerability due to its potential to allow local file inclusion in WordPress sites using the Global Logistics theme version 3.20 or earlier.
How do I fix CVE-2026-28018?
To fix CVE-2026-28018, update the Global Logistics theme to version 3.21 or later, which addresses this local file inclusion vulnerability.
Who is affected by CVE-2026-28018?
CVE-2026-28018 affects users of the WordPress Global Logistics theme version 3.20 and earlier.
What kind of vulnerability is CVE-2026-28018?
CVE-2026-28018 is classified as a Local File Inclusion vulnerability, which can lead to unauthorized file access on the server.
Can CVE-2026-28018 be exploited remotely?
Yes, CVE-2026-28018 could potentially be exploited remotely if an attacker can manipulate the parameters of include or require statements in the PHP application.