CVE-2026-28120: WordPress Dr.Patterson theme <= 1.3.2 - Local File Inclusion vulnerability
Published Mar 5, 2026
·Updated
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Dr.Patterson dr-patterson allows PHP Local File Inclusion.This issue affects Dr.Patterson: from n/a through <= 1.3.2.
Affected Software
1 affected component
ThemeREX Dr.Patterson<=1.3.2
Event History
Mar 5, 2026
CVE Published
via MITRE·05:54 AM
Data Sourced
via MITRE·05:54 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-28120?
The severity of CVE-2026-28120 is classified as critical due to its ability to expose local files on the server.
2
How do I fix CVE-2026-28120?
To fix CVE-2026-28120, update the Dr.Patterson theme to the latest version beyond 1.3.2.
3
What software is affected by CVE-2026-28120?
CVE-2026-28120 affects ThemeREX Dr.Patterson versions up to and including 1.3.2.
4
What type of vulnerability is CVE-2026-28120?
CVE-2026-28120 is a Local File Inclusion vulnerability that can lead to remote file inclusion attacks.
5
Can CVE-2026-28120 be exploited to execute arbitrary code?
Yes, CVE-2026-28120 can potentially be exploited to execute arbitrary code by allowing malicious files to be included.