CVE-2026-28062: WordPress Happy Baby theme <= 1.2.12 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Happy Baby happy-baby allows PHP Local File Inclusion.This issue affects Happy Baby: from n/a through <= 1.2.12.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28062?
CVE-2026-28062 has a high severity rating due to its potential for local file inclusion vulnerabilities.
How do I fix CVE-2026-28062?
To fix CVE-2026-28062, update the Happy Baby theme to version 1.2.13 or later.
What systems are affected by CVE-2026-28062?
CVE-2026-28062 affects the Happy Baby theme versions up to 1.2.12 in WordPress.
What is a Local File Inclusion vulnerability in CVE-2026-28062?
A Local File Inclusion vulnerability allows an attacker to include files on a server through the web browser, potentially leading to unauthorized access to sensitive data.
Who is the vendor for CVE-2026-28062?
The vendor for CVE-2026-28062 is ThemeREX, responsible for the Happy Baby theme.