CVE-2026-28020: WordPress Chroma theme <= 1.11 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Chroma chroma allows PHP Local File Inclusion.This issue affects Chroma: from n/a through <= 1.11.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The CVSS vector indicates that exploitation can be performed remotely without authentication or user interaction. However, the attack complexity is rated high, so successful exploitation depends on conditions not specified in the available data.
What is the potential impact if exploitation succeeds?
The reported CVSS impact is high for confidentiality, integrity, and availability. A successful attack could therefore have severe effects on affected site data and operation.
Which installations are in scope?
The issue affects the ThemeREX Chroma/WordPress Chroma theme through version 1.11. The available data does not state whether any particular default configuration or feature must be enabled.