CVE-2026-28097: WordPress Artrium theme <= 1.0.14 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Artrium artrium allows PHP Local File Inclusion.This issue affects Artrium: from n/a through <= 1.0.14.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28097?
CVE-2026-28097 has been classified as a high severity vulnerability due to its potential to allow unauthorized access to the file system.
How do I fix CVE-2026-28097?
To mitigate CVE-2026-28097, update the Artrium theme to version 1.0.15 or later immediately.
What type of vulnerability is CVE-2026-28097?
CVE-2026-28097 is a Local File Inclusion (LFI) vulnerability that can lead to Remote File Inclusion attacks.
Which versions of Artrium are affected by CVE-2026-28097?
CVE-2026-28097 affects all versions of the Artrium theme up to and including version 1.0.14.
Does CVE-2026-28097 affect other products?
CVE-2026-28097 specifically affects the ThemeREX Artrium theme on WordPress and does not apply to other themes or plugins.