CVE-2026-28063: WordPress Asia Garden theme <= 1.3.1 - Local File Inclusion vulnerability
Published Mar 5, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Asia Garden asia-garden allows PHP Local File Inclusion.This issue affects Asia Garden: from n/a through <= 1.3.1.
Affected Software
2 affected components
ThemeREX Asia Garden<=1.3.1
wordpress/asia-garden<=1.3.1
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28063?
CVE-2026-28063 has a high severity rating due to the potential for local file inclusion attacks.
2
How do I fix CVE-2026-28063?
To fix CVE-2026-28063, upgrade the Asia Garden theme to a version higher than 1.3.1.
3
Who is affected by CVE-2026-28063?
CVE-2026-28063 affects all users of the ThemeREX Asia Garden theme version 1.3.1 and below.
4
What type of vulnerability is CVE-2026-28063?
CVE-2026-28063 is classified as a Local File Inclusion (LFI) vulnerability.
5
Can CVE-2026-28063 lead to remote code execution?
While CVE-2026-28063 primarily allows local file inclusion, it may lead to remote code execution if exploited in conjunction with other vulnerabilities.