CVE-2026-28065: WordPress Eject theme <= 2.17 - Local File Inclusion vulnerability
Published Mar 5, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Eject eject allows PHP Local File Inclusion.This issue affects Eject: from n/a through <= 2.17.
Affected Software
2 affected components
ThemeREX Eject<=2.17
WordPress Eject<=2.17
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28065?
CVE-2026-28065 is classified as a high severity local file inclusion vulnerability.
2
How do I fix CVE-2026-28065?
To fix CVE-2026-28065, update the ThemeREX Eject theme to a version later than 2.17.
3
Who is affected by CVE-2026-28065?
CVE-2026-28065 affects users of the ThemeREX Eject theme versions up to and including 2.17.
4
What type of vulnerability is CVE-2026-28065?
CVE-2026-28065 is a local file inclusion vulnerability due to improper control of filename inclusion in PHP.
5
Can CVE-2026-28065 lead to remote code execution?
Yes, if successfully exploited, CVE-2026-28065 can potentially allow for remote code execution.