CVE-2026-28024: WordPress Helion theme <= 1.1.12 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Helion helion allows PHP Local File Inclusion.This issue affects Helion: from n/a through <= 1.1.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28024?
CVE-2026-28024 is classified as a high-severity vulnerability due to its potential for local file inclusion attacks.
How do I fix CVE-2026-28024?
To fix CVE-2026-28024, update the Helion theme to a version greater than 1.1.12 or apply any available security patches.
What impact does CVE-2026-28024 have on my website?
CVE-2026-28024 can allow attackers to execute arbitrary files on your server, leading to data compromise or full server control.
Who is affected by CVE-2026-28024?
CVE-2026-28024 affects users of the WordPress Helion theme version 1.1.12 and earlier.
Is CVE-2026-28024 actively exploited?
While there have been reports of exploitation attempts for CVE-2026-28024, specific incidents may vary and should be monitored for updates.