CVE-2026-48194: WordPress DukaMarket theme <= 1.3.0 - Local File Inclusion vulnerability
Published Oct 10, 2026
·Updated
Unauthenticated Local File Inclusion in DukaMarket <= 1.3.0 versions.
Affected Software
1 affected component
WordPress DukaMarket Theme<=1.3.0
Event History
Oct 10, 2026
CVE Published
via MITRE·07:35 PM
Data Sourced
via MITRE·07:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require a WordPress account or action from a site user?
No. The vulnerability is rated with no privileges required and no user interaction required, so an unauthenticated attacker can attempt exploitation without a WordPress account or victim participation.
2
Can the issue be exploited remotely?
Yes. The attack vector is network-based, indicating that exploitation can be attempted over the network rather than requiring local access to the server.
3
How difficult is exploitation expected to be?
The attack complexity is rated high. This indicates exploitation requires conditions beyond simply sending a basic request, although the available data does not specify those conditions.