CVE-2026-28085: WordPress Mahogany theme <= 2.9 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Mahogany mahogany allows PHP Local File Inclusion.This issue affects Mahogany: from n/a through <= 2.9.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28085?
CVE-2026-28085 has a high severity rating due to its potential for Remote File Inclusion and Local File Inclusion vulnerabilities.
How do I fix CVE-2026-28085?
To fix CVE-2026-28085, update the ThemeREX Mahogany theme to a version higher than 2.9.
What versions of WordPress Mahogany are affected by CVE-2026-28085?
CVE-2026-28085 affects WordPress Mahogany theme versions from n/a through 2.9.
What types of attacks can CVE-2026-28085 facilitate?
CVE-2026-28085 can facilitate attacks such as Local File Inclusion, allowing attackers to access sensitive files on the server.
Who should be concerned about CVE-2026-28085?
Website administrators using the affected version of the ThemeREX Mahogany theme should be particularly concerned about CVE-2026-28085.