CVE-2026-28060: WordPress S.King theme <= 1.5.3 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX S.King stephanie-king allows PHP Local File Inclusion.This issue affects S.King: from n/a through <= 1.5.3.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28060?
CVE-2026-28060 is classified as a critical Local File Inclusion vulnerability that allows unauthorized access to sensitive files.
How do I fix CVE-2026-28060?
To fix CVE-2026-28060, update the S.King theme to version 1.5.4 or later as this version contains patches for the vulnerable code.
What are the potential impacts of CVE-2026-28060?
The potential impacts of CVE-2026-28060 include arbitrary file access and remote code execution, which could compromise website security.
Who is affected by CVE-2026-28060?
Users of the ThemeREX S.King theme version 1.5.3 or earlier are affected by CVE-2026-28060.
Is there a workaround for CVE-2026-28060?
A temporary workaround for CVE-2026-28060 may involve disabling the vulnerable features or restricting access to the theme files until an update can be applied.