CVE-2026-28090: WordPress Gamezone theme <= 1.1.11 - Local File Inclusion vulnerability
Published Mar 5, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Gamezone gamezone allows PHP Local File Inclusion.This issue affects Gamezone: from n/a through <= 1.1.11.
Affected Software
2 affected components
ThemeREX Gamezone<=1.1.11
WordPress Gamezone theme<=1.1.11
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28090?
CVE-2026-28090 is regarded as a high severity vulnerability that allows local file inclusion on the WordPress Gamezone theme.
2
How do I fix CVE-2026-28090?
To fix CVE-2026-28090, update the WordPress Gamezone theme to version 1.1.12 or above to patch the vulnerability.
3
What software is affected by CVE-2026-28090?
CVE-2026-28090 affects the ThemeREX Gamezone theme versions up to and including 1.1.11.
4
What type of vulnerability is CVE-2026-28090?
CVE-2026-28090 is classified as a Local File Inclusion (LFI) vulnerability.
5
Can CVE-2026-28090 lead to remote attacks?
Yes, CVE-2026-28090 can potentially lead to remote attacks due to improper control of file inclusion.