CVE-2026-28081: WordPress Windsor theme <= 2.5.0 - Local File Inclusion vulnerability
Published Mar 5, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Windsor windsor allows PHP Local File Inclusion.This issue affects Windsor: from n/a through <= 2.5.0.
Affected Software
2 affected components
ThemeREX Windsor<=2.5.0
wordpress/windsor<=2.5.0
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28081?
CVE-2026-28081 is classified as a high severity vulnerability due to its potential for local file inclusion and execution of arbitrary PHP code.
2
How do I fix CVE-2026-28081?
To fix CVE-2026-28081, upgrade the ThemeREX Windsor theme to version 2.5.1 or later.
3
What versions are affected by CVE-2026-28081?
CVE-2026-28081 affects ThemeREX Windsor versions 2.5.0 and earlier.
4
What type of vulnerability is CVE-2026-28081?
CVE-2026-28081 is a Local File Inclusion vulnerability that allows unauthorized access to files on the server.
5
Can CVE-2026-28081 lead to remote code execution?
Yes, CVE-2026-28081 can potentially lead to remote code execution if exploited by an attacker.