CVE-2026-42777: WordPress Aalto theme <= 1.8 - Local File Inclusion vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated Local File Inclusion in Aalto <= 1.8 versions.
Affected Software
1 affected component
WordPress Aalto theme<=1.8
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The issue is unauthenticated, so an attacker does not need a WordPress account or other prior privileges. It is remotely reachable over the network, although exploitation has high attack complexity.
2
Which installations are affected?
WordPress sites using the Aalto theme version 1.8 or earlier are affected according to the available information.
3
What is the potential impact if exploitation succeeds?
The reported impact includes high confidentiality, integrity, and availability effects. Successful exploitation could therefore expose sensitive information and affect site data or availability.