CVE-2026-42724: WordPress CleanSkin theme <= 1.5.0 - Local File Inclusion vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated Local File Inclusion in CleanSkin <= 1.5.0 versions.
Affected Software
1 affected component
WordPress CleanSkin theme<=1.5.0
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. Exploitation is network-accessible, although the high attack complexity indicates additional conditions are required.
2
Which installations are affected?
WordPress sites using the CleanSkin theme version 1.5.0 or earlier are affected. The provided data does not state whether the vulnerable functionality is enabled in the theme's default configuration.
3
What is the potential impact?
Successful exploitation can lead to local file inclusion and is rated high severity, with high impacts to confidentiality, integrity, and availability.