CVE-2026-66656: WordPress Foton Core plugin <= 1.1.1 - Local File Inclusion vulnerability
Published Aug 13, 2026
·Updated
Unauthenticated Local File Inclusion in Foton Core <= 1.1.1 versions.
Affected Software
1 affected component
WordPress Foton Core plugin<=1.1.1
Event History
Aug 13, 2026
CVE Published
via MITRE·01:37 PM
Data Sourced
via MITRE·01:37 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-66656?
CVE-2026-66656 has a severity rating of 8.1, indicating a high risk vulnerability.
2
What type of vulnerability is CVE-2026-66656?
CVE-2026-66656 is a Local File Inclusion (LFI) vulnerability affecting the Foton Core plugin.
3
How do I fix CVE-2026-66656?
To mitigate CVE-2026-66656, update the Foton Core plugin to version 1.1.2 or higher.
4
What versions of the Foton Core plugin are affected by CVE-2026-66656?
CVE-2026-66656 affects Foton Core plugin versions 1.1.1 and earlier.
5
Is authentication required to exploit CVE-2026-66656?
No, CVE-2026-66656 can be exploited without authentication.