CVE-2026-28029: WordPress EmojiNation theme <= 1.0.12 - Local File Inclusion vulnerability
Published Mar 5, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX EmojiNation emojination allows PHP Local File Inclusion.This issue affects EmojiNation: from n/a through <= 1.0.12.
Affected Software
2 affected components
ThemeREX EmojiNation<=1.0.12
WordPress EmojiNation<=1.0.12
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
The issue affects ThemeREX EmojiNation installations through version 1.0.12. The provided data does not identify a fixed release.
2
Can this be exploited remotely without authentication?
The CVSS vector indicates network-based attack access and no privileges or user interaction are required. However, the attack complexity is rated high.
3
What is the potential impact if exploitation succeeds?
The CVSS rating indicates high confidentiality, integrity, and availability impact. The weakness is a PHP local file inclusion issue, which may allow an attacker to include local files.