CVE-2026-28064: WordPress Edge Decor theme <= 2.2 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Edge Decor edge-decor allows PHP Local File Inclusion.This issue affects Edge Decor: from n/a through <= 2.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28064?
CVE-2026-28064 is a high-severity vulnerability due to its potential for local file inclusion and remote code execution.
How do I fix CVE-2026-28064?
To fix CVE-2026-28064, update the Edge Decor theme to version 2.3 or later which addresses the local file inclusion vulnerability.
What systems are affected by CVE-2026-28064?
CVE-2026-28064 affects WordPress Edge Decor theme versions up to and including 2.2.
What kind of attacks can CVE-2026-28064 facilitate?
CVE-2026-28064 can facilitate local file inclusion attacks, allowing attackers to access sensitive files on the server.
Is CVE-2026-28064 a remote code execution vulnerability?
CVE-2026-28064 is classified as a local file inclusion vulnerability, but it could potentially lead to remote code execution under certain conditions.