CVE-2026-28128: WordPress Verse theme <= 1.7.0 - Local File Inclusion vulnerability
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Verse verse allows PHP Local File Inclusion.This issue affects Verse: from n/a through <= 1.7.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-28128?
CVE-2026-28128 is rated with a severity that can allow attackers to exploit Local File Inclusion vulnerabilities in versions of the ThemeREX Verse theme up to 1.7.0.
How do I fix CVE-2026-28128?
To fix CVE-2026-28128, upgrade the ThemeREX Verse theme to a version higher than 1.7.0 to eliminate the Local File Inclusion vulnerability.
What causes CVE-2026-28128?
CVE-2026-28128 is caused by improper control of filename parameters in PHP include or require statements, creating a risk for Local File Inclusion.
Which versions of ThemeREX Verse are affected by CVE-2026-28128?
CVE-2026-28128 affects ThemeREX Verse theme versions from n/a through 1.7.0 inclusive.
What can an attacker do with CVE-2026-28128?
An attacker can exploit CVE-2026-28128 to execute arbitrary PHP code on the server via Local File Inclusion, potentially compromising the site.