CVE-2026-28066: WordPress Legrand theme <= 2.17 - Local File Inclusion vulnerability
Published Mar 5, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Legrand legrand allows PHP Local File Inclusion.This issue affects Legrand: from n/a through <= 2.17.
Affected Software
2 affected components
ThemeREX Legrand<=2.17
WordPress Legrand<=2.17
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28066?
CVE-2026-28066 is classified as a high-severity vulnerability due to its ability to allow local file inclusion.
2
How do I fix CVE-2026-28066?
To fix CVE-2026-28066, update the ThemeREX Legrand theme to version 2.18 or later.
3
What are the consequences of exploiting CVE-2026-28066?
Exploiting CVE-2026-28066 can lead to unauthorized access to sensitive files on the server.
4
Which versions of WordPress Legrand are affected by CVE-2026-28066?
CVE-2026-28066 affects WordPress Legrand theme versions up to and including 2.17.
5
Is there any immediate mitigation for CVE-2026-28066?
As an immediate mitigation for CVE-2026-28066, disable or remove the affected theme until it is updated.